CVE-2017-3073: Adobe Flash Player
High severity, CVSS 8.8. EPSS: 4.9% chance of exploitation in the next 30 days.
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when handling multiple mask properties of display objects, aka memory corruption. Successful exploitation could lead to arbitrary code execution.
Affected products
- Adobe Flash Player: up to and including 25.0.0.148
- Adobe Flash Player Desktop Runtime: up to and including 25.0.0.163; up to and including 25.0.0.148
- Red Hat Enterprise Linux: version 6.0 only
- Red Hat Enterprise Linux Desktop: version 6.0 only
- Red Hat Enterprise Linux Workstation: version 6.0 only
Published 2017-05-09. Last modified 2026-06-17.