CVE-2017-3075: Adobe Flash Player

Critical severity, CVSS 9.8. EPSS: 8.7% chance of exploitation in the next 30 days.

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability when manipulating the ActionsScript 2 XML class. Successful exploitation could lead to arbitrary code execution.

Affected products

  • Adobe Flash Player: up to and including 25.0.0.171

Published 2017-06-20. Last modified 2026-06-17.