← Back to browse · API

CVE-2017-11292

Severity
HIGH
CVSS
8.8
EPSS
0.12104
Risk score
64.44
CISA KEV
Yes
PoC
No
Published
2017-10-21
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2017-2926, GHSA-F6X6-GF9M-8CC3
Products
Adobe:Flash Player, n/a:Adobe Flash Player version 27.0.0.159 and earlier Adobe Flash Player version 27.0.0.159 and earlier
Sources
cisa.gov CVE-2017-11292
euvd EUVD-2017-2926

Description

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.

References