Junglewise Threat Intelligence

CVE-2017-11292: Adobe Flash Player Type Confusion Vulnerability

CVE-2017-11292 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-03

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Flash Player contains a type confusion vulnerability due to a flawed bytecode verification procedure. This flaw allows an untrusted value to be used in an array index calculation, potentially leading to arbitrary code execution.

Affected products

  • Adobe Flash Player 27.0.0.159 and earlier

Timeline

  • 2017-10-16: advisory: Adobe released security bulletin APSB17-32
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2017-10-16: patched: Patch released in version 27.0.0.170

Related threats