← Back to CVE List
Vulnerability Intelligence Report
Adobe Flash Player Type Confusion Vulnerability

CVE-2017-11292

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:12.10%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-843 ↗CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

Affected Products & Versions

Vendor Product Affected Versions
adobe flash_player_desktop_runtime all
apple mac_os_x all
linux linux_kernel all
microsoft windows all
adobe flash_player all
microsoft windows_10 all
microsoft windows_8.1 all
google chrome_os all
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_server 6.0
redhat enterprise_linux_workstation 6.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
12.104%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityAdobe Systems Incorporated · Vendor · USA
Reserved2017-07-13T00:00:00
Published2017-10-21T05:00:00
Patch Date2017-10-21
Last Updated2025-10-21T23:55:30

LINK COPIED TO CLIPBOARD