SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2016-4117

Adobe Flash Player Arbitrary Code Execution Vulnerability

KEVCRITICAL 9.8EPSS 94.4%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
94.35% probability · 100th percentile
CISA KEV
Listed 3 March 2022 · due 24 March 2022 · used in ransomware campaigns
Affected
adobe/flash player · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server from rhui · redhat/enterprise linux workstation · opensuse/evergreen · opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise workstation extension
Source
psirt@adobe.com

CISA notes

The impacted product is end-of-life and should be disconnected if still in use. https://nvd.nist.gov/vuln/detail/CVE-2016-4117

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.