Microsoft Windows update for Adobe Flash

Published: 2017-11-14 | Updated: 2017-11-14
Severity High
Patch available YES
Number of vulnerabilities 5
CVE ID CVE-2017-3112
CVE-2017-3114
CVE-2017-11213
CVE-2017-11215
CVE-2017-11225
CWE ID CWE-125
CWE-416
Exploitation vector Network
Public exploit N/A
Vulnerable software Adobe Flash Player Subscribe
Vendor Microsoft

Security Advisory

1) Out-of-bounds read

Severity: Low

CVSSv3: 4.6 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2017-3112

CWE-ID: CWE-125 - Out-of-bounds Read

Description

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to out-of-bounds read. A remote attacker can gain access to arbitrary data.

Mitigation

Install updates from Microsoft website.

Vulnerable software versions

Adobe Flash Player: on Windows 8.1 for 32-bit systems, on Windows 8.1 for x64-based systems, on Windows 10 for 32-bit Systems, on Windows 10 for x64-based Systems, on Windows 10 Version 1511 for 32-bit Systems, on Windows 10 Version 1511 for x64-based Systems, on Windows 10 Version 1607 for 32-bit Systems, on Windows 10 Version 1607 for x64-based Systems, on Windows 10 Version 1703 for 32-bit Systems, on Windows 10 Version 1703 for x64-based Systems, on Windows 10 Version 1709 for 32-bit Systems, on Windows 10 Version 1709 for 64-based Systems, on Windows RT 8.1, on Windows Server 2012, on Windows Server 2012 R2, on Windows Server 2016

CPE External links

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV170019

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Out-of-bounds read

Severity: Low

CVSSv3: 4.6 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2017-3114

CWE-ID: CWE-125 - Out-of-bounds Read

Description

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to out-of-bounds read. A remote attacker can gain access to arbitrary data.

Mitigation

Install updates from Microsoft website.

Vulnerable software versions

Adobe Flash Player: on Windows 8.1 for 32-bit systems, on Windows 8.1 for x64-based systems, on Windows 10 for 32-bit Systems, on Windows 10 for x64-based Systems, on Windows 10 Version 1511 for 32-bit Systems, on Windows 10 Version 1511 for x64-based Systems, on Windows 10 Version 1607 for 32-bit Systems, on Windows 10 Version 1607 for x64-based Systems, on Windows 10 Version 1703 for 32-bit Systems, on Windows 10 Version 1703 for x64-based Systems, on Windows 10 Version 1709 for 32-bit Systems, on Windows 10 Version 1709 for 64-based Systems, on Windows RT 8.1, on Windows Server 2012, on Windows Server 2012 R2, on Windows Server 2016

CPE External links

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV170019

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Out-of-bounds read

Severity: Low

CVSSv3: 4.6 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2017-11213

CWE-ID: CWE-125 - Out-of-bounds Read

Description

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to out-of-bounds read. A remote attacker can gain access to arbitrary data.

Mitigation

Install updates from Microsoft website.

Vulnerable software versions

Adobe Flash Player: on Windows 8.1 for 32-bit systems, on Windows 8.1 for x64-based systems, on Windows 10 for 32-bit Systems, on Windows 10 for x64-based Systems, on Windows 10 Version 1511 for 32-bit Systems, on Windows 10 Version 1511 for x64-based Systems, on Windows 10 Version 1607 for 32-bit Systems, on Windows 10 Version 1607 for x64-based Systems, on Windows 10 Version 1703 for 32-bit Systems, on Windows 10 Version 1703 for x64-based Systems, on Windows 10 Version 1709 for 32-bit Systems, on Windows 10 Version 1709 for 64-based Systems, on Windows RT 8.1, on Windows Server 2012, on Windows Server 2012 R2, on Windows Server 2016

CPE External links

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV170019

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Use-after-free error

Severity: High

CVSSv3: 8.7 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2017-11215

CWE-ID: CWE-416 - Use After Free

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to a use-after-free error. A remote attacker can trigger memory corruption and execute arbitrary code with privileges of the current user.

Successful exploitation of the vulnerability may result in system compromise.

Mitigation

Install updates from Microsoft website.

Vulnerable software versions

Adobe Flash Player: on Windows 8.1 for 32-bit systems, on Windows 8.1 for x64-based systems, on Windows 10 for 32-bit Systems, on Windows 10 for x64-based Systems, on Windows 10 Version 1511 for 32-bit Systems, on Windows 10 Version 1511 for x64-based Systems, on Windows 10 Version 1607 for 32-bit Systems, on Windows 10 Version 1607 for x64-based Systems, on Windows 10 Version 1703 for 32-bit Systems, on Windows 10 Version 1703 for x64-based Systems, on Windows 10 Version 1709 for 32-bit Systems, on Windows 10 Version 1709 for 64-based Systems, on Windows RT 8.1, on Windows Server 2012, on Windows Server 2012 R2, on Windows Server 2016

CPE External links

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV170019

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Use-after-free error

Severity: High

CVSSv3: 8.7 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2017-11225

CWE-ID: CWE-416 - Use After Free

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to a use-after-free error. A remote attacker can trigger memory corruption and execute arbitrary code with privileges of the current user.

Successful exploitation of the vulnerability may result in system compromise.

Mitigation

Install updates from Microsoft website.

Vulnerable software versions

Adobe Flash Player: on Windows 8.1 for 32-bit systems, on Windows 8.1 for x64-based systems, on Windows 10 for 32-bit Systems, on Windows 10 for x64-based Systems, on Windows 10 Version 1511 for 32-bit Systems, on Windows 10 Version 1511 for x64-based Systems, on Windows 10 Version 1607 for 32-bit Systems, on Windows 10 Version 1607 for x64-based Systems, on Windows 10 Version 1703 for 32-bit Systems, on Windows 10 Version 1703 for x64-based Systems, on Windows 10 Version 1709 for 32-bit Systems, on Windows 10 Version 1709 for 64-based Systems, on Windows RT 8.1, on Windows Server 2012, on Windows Server 2012 R2, on Windows Server 2016

CPE External links

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV170019

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.