Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable type confusion vulnerability related to the MessageChannel class. Successful exploitation could lead to arbitrary code execution.
https://security.gentoo.org/glsa/201702-20
https://helpx.adobe.com/security/products/flash-player/apsb17-04.html
http://www.securitytracker.com/id/1037815