Kaspersky ID:
KLA10936
Detect Date:
01/10/2017
Updated:
01/22/2024

Description

Multiple serious vulnerabilities have been found in Adobe Flash Player. Malicious users can exploit these vulnerabilities to bypass security restrictions, obtain sensitive information or execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. Vulnerability related to handling TCP connections can be exploited remotely to bypass security restrictions;
  2. Use-after-free vulnerabilities in the ActionScript MovieClip and FileReference classes (when using class inheritance) can be exploited remotely to execute arbitrary code;
  3. Heap buffer overflow vulnerabilities occuring while processing Adobe Texture Format files or Flash Video container file format can be exploited remotely to execute arbitrary code;
  4. Heap buffer overflow vulnerability related to texture compression can be exploited remotely to execute arbitrary code;
  5. Memory corruption vulnerability in the JPEG XR codec can be exploited remotely to execute arbitrary code;
  6. Memory corruption vulnerabilities related to processing of atoms of MP4 files, setting visual mode effects and parsing metadata can be exploited remotely to execute arbitrary code;
  7. Memory corruption vulnerability occuring while manipulating a display list because of a concurrency error can be exploited remotely to execute arbitrary code.

Technical details

To update Adobe Flash Player ActiveX (detected as Flash.ocx) on Windows 8 and higher, install latest updates from Control Panel

Original advisories

Exploitation

Public exploits exist for this vulnerability.

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Related products

CVE list

  • CVE-2017-2925
    critical
  • CVE-2017-2926
    critical
  • CVE-2017-2927
    critical
  • CVE-2017-2928
    critical
  • CVE-2017-2930
    critical
  • CVE-2017-2931
    critical
  • CVE-2017-2932
    critical
  • CVE-2017-2933
    critical
  • CVE-2017-2934
    critical
  • CVE-2017-2935
    critical
  • CVE-2017-2936
    critical
  • CVE-2017-2937
    critical
  • CVE-2017-2938
    warning

Read more

Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com

Found an inaccuracy in the description of this vulnerability? Let us know!
Kaspersky Next
Let’s go Next: redefine your business’s cybersecurity
Learn more
New Kaspersky!
Your digital life deserves complete protection!
Learn more
Confirm changes?
Your message has been sent successfully.