Business logic error in Adobe Flash Player - CVE-2017-11305

 

Business logic error in Adobe Flash Player - CVE-2017-11305

Published: December 12, 2017


Vulnerability identifier: #VU9614
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-11305
CWE-ID: CWE-840
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify data on the target system.

The weakness exists due to business logic error. A remote attacker can reset global settings preference file.

Affected software

Adobe Flash Player
Adobe Flash Player for Microsoft Windows
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation

How to mitigate CVE-2017-11305

Update to version 28.0.0.126.


External References

Related Security Bulletins