PatchSiren cyber security CVE debrief
CVE-2017-2982 Adobe CVE debrief
CVE-2017-2982 is a high-severity Adobe Flash Player use-after-free vulnerability in a routine related to player shutdown. Adobe and NVD identify affected Flash Player builds as versions 24.0.0.194 and earlier, and the issue can lead to arbitrary code execution if successfully exploited. The NVD CVSS 3.1 vector shows network attack conditions with user interaction required.
- Vendor
- Adobe
- Product
- Flash Player
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-15
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-15
- Advisory updated
- 2026-05-13
Who should care
Organizations and users that still run Adobe Flash Player, including the Flash Player desktop runtime and browser-integrated Flash deployments listed in the NVD CPEs (Chrome, Edge, Internet Explorer). Security teams should treat this as important wherever legacy Flash components remain present.
Technical summary
NVD classifies the weakness as CWE-416 (use after free). The vulnerability is described as occurring in a routine related to player shutdown. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating remote reachability but requiring user interaction. NVD CPE entries mark Adobe Flash Player versions up to and including 24.0.0.194 as vulnerable for the listed Flash Player product variants.
Defensive priority
High priority. This is a remotely reachable, user-interaction-dependent code execution flaw in a widely deployed legacy product. Prioritize removal or patching of affected Flash Player installations and confirm that no vulnerable Flash runtime remains in supported or legacy environments.
Recommended defensive actions
- Apply the Adobe security update referenced by APSB17-04 for affected Flash Player installations.
- Remove or disable Adobe Flash Player wherever it is no longer required.
- Inventory systems for Flash Player desktop runtime and browser-integrated Flash instances listed in the NVD CPEs.
- Verify that installed Flash Player versions are newer than 24.0.0.194 or otherwise no longer present.
- Use browser and endpoint controls to block legacy Flash content until remediation is complete.
Evidence notes
The source corpus states that Adobe Flash Player versions 24.0.0.194 and earlier contain an exploitable use-after-free vulnerability related to player shutdown. NVD assigns CWE-416 and CVSS 3.1 vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The NVD CPE criteria list Adobe Flash Player variants for Chrome, Edge, Internet Explorer, and the desktop runtime as vulnerable through 24.0.0.194. Adobe’s advisory APSB17-04 is referenced as the vendor patch reference in the NVD record.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-2982 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-2982
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-2982 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2982
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://helpx.adobe.com/security/products/flash-player/apsb17-04.html
[email protected] - Patch, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201702-20
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.