CVE-2017-11215 PUBLISHED

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.

EPSS 5.82% · 90.5th percentile

Risk Scores

EPSS Score
5.82%
90.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSflashplugin-nonfree0, 11.2.202.540ubuntu2, 11.2.202.548ubuntu1
Ubuntu:14.04:LTSflashplugin-nonfree11.2.202.481ubuntu0.14.04.1, 11.2.202.481ubuntu0.14.04.2, 11.2.202.491ubuntu0.14.04.1

Timeline

References

Open in Interactive Console →