EXPOSURES › CVE-2017-11292
CVE-2017-11292
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Flash Player's unpatched type confusion vulnerability allowed remote code execution, proving that end-of-life software remains a perpetual security liability.
Adobe Flash Player, discontinued in December 2020, contained a type confusion vulnerability enabling remote code execution. Because the product reached end-of-life with no further security updates, any remaining installations are perpetually vulnerable to unpatched exploits. DIB organizations must ensure all legacy software is fully retired to avoid exposure to actively exploited vulnerabilities.
Shame score — The vendor discontinued the product without ensuring a safe transition, leaving organizations with a perpetual security liability that was actively exploited in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |