Lucene search

K
nessusTenable700058.PRM
HistoryApr 17, 2017 - 12:00 a.m.

Flash Player < 25.0.0.148 Multiple RCE (APSB17-10)

2017-04-1700:00:00
Tenable
www.tenable.com
18

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.73

Percentile

98.2%

Versions of Adobe Flash Player prior to 25.0.0.148 are unpatched, and therefore affected by the following RCE vulnerabilities :

  • A use-after-free error exists that is triggered when handling specially crafted ‘ByteArray’ objects. This may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. (CVE-2017-3058, CVE-2017-3059)
  • A flaw exists that is triggered as certain input is not properly validated when parsing specially crafted SWF content. This may allow a context-dependent attacker to corrupt memory and potentially execute arbitrary code. (CVE-2017-3060)
  • A use-after-free error exists that may allow a context-dependent attacker to dereference already freed memory and potentially execute arbitrary code. No further details have been provided. (CVE-2017-3061, CVE-2017-3062, CVE-2017-3063)
  • A flaw exists that is triggered as certain input is not properly validated. This may allow a context-dependent attacker to corrupt memory and potentially execute arbitrary code. No further details have been provided. (CVE-2017-3064)
Binary data 700058.prm

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.73

Percentile

98.2%