Vulnerability Description
Adobe Shockwave versions 12.2.7.197 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to escalation of privilege.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Shockwave Player | <= 12.2.7.197 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/96863
- http://www.securitytracker.com/id/1037993
- https://helpx.adobe.com/security/products/shockwave/apsb17-08.htmlVendor Advisory
- http://www.securityfocus.com/bid/96863
- http://www.securitytracker.com/id/1037993
- https://helpx.adobe.com/security/products/shockwave/apsb17-08.htmlVendor Advisory
FAQ
What is CVE-2017-2983?
CVE-2017-2983 is a vulnerability with a CVSS score of 7.8 (HIGH). Adobe Shockwave versions 12.2.7.197 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to escalation of privilege.
How severe is CVE-2017-2983?
CVE-2017-2983 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-2983?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Shockwave Player.