CVE-2017-3069: Adobe Flash Player

High severity, CVSS 8.8. EPSS: 5% chance of exploitation in the next 30 days.

Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the BlendMode class. Successful exploitation could lead to arbitrary code execution.

Affected products

  • Adobe Flash Player: up to and including 25.0.0.148
  • Adobe Flash Player Desktop Runtime: up to and including 25.0.0.163; up to and including 25.0.0.148
  • Red Hat Enterprise Linux: version 6.0 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2017-05-09. Last modified 2026-06-17.