Skip to content
COOEY

EXPOSURES › CVE-2017-11292

CVE-2017-11292

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-11292 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatchedransomware

Adobe Flash Player's unpatched type confusion vulnerability allowed remote code execution, proving that end-of-life software remains a perpetual security liability.

Adobe Flash Player, discontinued in December 2020, contained a type confusion vulnerability enabling remote code execution. Because the product reached end-of-life with no further security updates, any remaining installations are perpetually vulnerable to unpatched exploits. DIB organizations must ensure all legacy software is fully retired to avoid exposure to actively exploited vulnerabilities.

Shame score — The vendor discontinued the product without ensuring a safe transition, leaving organizations with a perpetual security liability that was actively exploited in the wild.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized