High severity8.8NVD Advisory· Published May 9, 2017· Updated May 13, 2026
CVE-2017-3073
CVE-2017-3073
Description
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when handling multiple mask properties of display objects, aka memory corruption. Successful exploitation could lead to arbitrary code execution.
Affected products
7- cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:*Range: <=25.0.0.163
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:*+ 2 more
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:*range: <=25.0.0.148
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:*range: <=25.0.0.148
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:*range: <=25.0.0.148
- cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- helpx.adobe.com/security/products/flash-player/apsb17-15.htmlnvdPatchVendor Advisory
- www.securityfocus.com/bid/98349nvdBroken LinkThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1038427nvdBroken LinkThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2017:1219nvdThird Party Advisory
- security.gentoo.org/glsa/201705-12nvdThird Party Advisory
News mentions
0No linked articles in our index yet.