CVE-2017-11215

Description

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
5.822

Associated Vulnerability

VulnerabilityOS Platform
November 2017 Adobe Flash Security UpdateSecurity Update for Adobe Flash Player for Windows 10 Version 1511 for x64-based Systems (KB4048951)Windows
November 2017 Adobe Flash Security UpdateSecurity Update for Adobe Flash Player for Windows 10 Version 1511 for x86-based Systems (KB4048951)Windows
November 2017 Adobe Flash Security UpdateSecurity Update for Adobe Flash Player for Windows 10 Version 1607 for x64-based Systems (KB4048951)Windows
November 2017 Adobe Flash Security UpdateSecurity Update for Adobe Flash Player for Windows 10 Version 1607 for x86-based Systems (KB4048951)Windows
November 2017 Adobe Flash Security Update2017-11 Security Update for Adobe Flash Player for Windows 10 Version 1703 for x64-based Systems (KB4048951)Windows
November 2017 Adobe Flash Security UpdateSecurity Update for Adobe Flash Player for Windows 10 Version 1703 for x86-based Systems (KB4048951)Windows
November 2017 Adobe Flash Security UpdateSecurity Update for Adobe Flash Player for Windows 10 Version 1709 for x64-based Systems (KB4048951)Windows
November 2017 Adobe Flash Security UpdateSecurity Update for Adobe Flash Player for Windows 10 Version 1709 for x86-based Systems (KB4048951)Windows
November 2017 Adobe Flash Security UpdateSecurity Update for Adobe Flash Player for Windows Server 2016 for x64-based Systems (KB4048951)Windows
November 2017 Adobe Flash Security UpdateSecurity Update for Adobe Flash Player for Windows 10 Version 1507 for x64-based Systems (KB4048951)Windows
November 2017 Adobe Flash Security UpdateSecurity Update for Adobe Flash Player for Windows Server 2012 for x64-based Systems (KB4048951)Windows
November 2017 Adobe Flash Security UpdateSecurity Update for Adobe Flash Player for Windows Server 2012 R2 for x64-based Systems (KB4048951)Windows
November 2017 Adobe Flash Security UpdateSecurity Update for Adobe Flash Player for Windows 8.1 for x64-based Systems (KB4048951)Windows
November 2017 Adobe Flash Security UpdateSecurity Update for Adobe Flash Player for Windows 8.1 for x86-based Systems (KB4048951)Windows
Updates for Google Chrome (65.0.3325.146)Windows
Updates for Google Chrome (x64) (65.0.3325.146)Windows
Upgrade Adobe flash player 27.0.0.183 to latest versionWindows
Vulnerabilities CVE-2017-11213,CVE-2017-11215,CVE-2017-11225,CVE-2017-3112,CVE-2017-3114 are affected in Adobe Flash Player Plugin 27.0.0.183Windows
Vulnerabilities CVE-2017-11213,CVE-2017-11215,CVE-2017-11225,CVE-2017-3112,CVE-2017-3114 are affected in Adobe Flash Player PPAPI 27.0.0.183Windows
Multiple vulnerabilities are fixed in Update for Google Chrome For Mac (65.0.3325.146)Mac
Updates for Google Chrome (65.0.3325.146) (For Ubuntu)Linux
Updates for Google Chrome (65.0.3325.146) (For Debian)Linux
Updates for Google Chrome (65.0.3325.146) (For Centos)Linux
Updates for Google Chrome (65.0.3325.146) (For RedHat)Linux
Updates for Google Chrome (65.0.3325.146) (For Suse)Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-23424Security Update for Adobe Flash Player for Windows 10 Version 1511 for x64-based Systems (KB4048951)
PATCH-23423Security Update for Adobe Flash Player for Windows 10 Version 1511 for x86-based Systems (KB4048951)
PATCH-23426Security Update for Adobe Flash Player for Windows 10 Version 1607 for x64-based Systems (KB4048951)
PATCH-23425Security Update for Adobe Flash Player for Windows 10 Version 1607 for x86-based Systems (KB4048951)
PATCH-234282017-11 Security Update for Adobe Flash Player for Windows 10 Version 1703 for x64-based Systems (KB4048951)
PATCH-23427Security Update for Adobe Flash Player for Windows 10 Version 1703 for x86-based Systems (KB4048951)
PATCH-23430Security Update for Adobe Flash Player for Windows 10 Version 1709 for x64-based Systems (KB4048951)
PATCH-23429Security Update for Adobe Flash Player for Windows 10 Version 1709 for x86-based Systems (KB4048951)
PATCH-23431Security Update for Adobe Flash Player for Windows Server 2016 for x64-based Systems (KB4048951)
PATCH-23422Security Update for Adobe Flash Player for Windows 10 Version 1507 for x64-based Systems (KB4048951)
PATCH-23419 Security Update for Adobe Flash Player for Windows Server 2012 for x64-based Systems (KB4048951)
PATCH-23420Security Update for Adobe Flash Player for Windows Server 2012 R2 for x64-based Systems (KB4048951)
PATCH-23418 Security Update for Adobe Flash Player for Windows 8.1 for x64-based Systems (KB4048951)
PATCH-23417Security Update for Adobe Flash Player for Windows 8.1 for x86-based Systems (KB4048951)
PATCH-307219Updates for Google Chrome (65.0.3325.146)
PATCH-307220Updates for Google Chrome (x64) (65.0.3325.146)
PATCH-609673Google Chrome for Mac (132.0.6834.83, 132.0.6834.84)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234