LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-11292: Adobe Flash Player Type Confusion Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-11292 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.

CVE-2017-11292 is a type confusion vulnerability in Adobe Flash Player that can allow remote code execution. For IT and security teams, it matters because Flash content was historically embedded in browsers and enterprise applications; successful abuse can let an attacker run code in the context of the user or process that loads the flawed component. The product is end-of-life, and CISA directs that remaining installations should be disconnected.

Public detail is limited to the class of flaw and the remote-code-execution outcome. Confirm all version, configuration, and fix specifics against the vendor advisory before acting.

How it works

This issue is classified as CWE-843 (type confusion). In type-confusion flaws, the program treats a resource or object as one type when it is actually another. That mismatch can corrupt memory layout or control flow in ways an attacker can influence.

In the Flash Player class of products, an attacker typically needs the victim to load malicious Flash content—commonly via a crafted web page, document, or other container that invokes the player. Once the confused type is exercised, the attacker may achieve code execution with the privileges of the Flash process or the hosting application. Exact trigger conditions and exploit mechanics are not provided here; treat any public proof-of-concept claims cautiously and validate against the vendor advisory and your own lab analysis.

Am I affected? How to find it in your systems

Adobe Flash Player historically ran as a browser plugin, an ActiveX control, a PPAPI/NPAPI component, or as a standalone projector, and was sometimes bundled with enterprise apps or kiosks. Because the product is end-of-life, any remaining presence is a liability.

How to remediate

The primary remediation path for an end-of-life product is removal, not patching in place. CISA’s required action is that the impacted product should be disconnected if still in use.

If you can't patch immediately

When immediate removal is blocked by a business dependency, apply compensating controls while you accelerate replacement.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities can lead to endpoint takeover, credential theft, and follow-on data exposure. Known ransomware use is not documented for this CVE in the provided facts; still treat any confirmed compromise as a full incident. Isolate affected hosts, preserve volatile evidence, rotate credentials accessible from those systems, and perform scoped hunting for lateral movement. As a routine check, users and administrators can run a free exposure scan of their work email addresses against known breach datasets to see whether credentials or personal data have appeared in prior incidents, then force password resets and enable phishing-resistant MFA where exposure is found.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Flash Player
WeaknessCWE-843
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities