VulnerabilityAnalyzed
CVE-2016-4171
Adobe Flash Player Remote Code Execution Vulnerability
KEVCRITICAL 9.8EPSS 20.2%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 20.21% probability · 97th percentile
- CISA KEV
- Listed 25 March 2022 · due 15 April 2022
- Affected
- adobe/flash player · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise workstation extension
- Source
- psirt@adobe.com
CISA notes
The impacted product is end-of-life and should be disconnected if still in use. https://nvd.nist.gov/vuln/detail/CVE-2016-4171
References
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/91184Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036094Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:1238Third Party Advisory
- https://helpx.adobe.com/security/products/flash-player/apsa16-03.htmlVendor Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb16-18.htmlVendor Advisory
- https://security.gentoo.org/glsa/201606-08Third Party Advisory
- https://www.kb.cert.org/vuls/id/748992Third Party Advisory, US Government Resource
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/91184Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036094Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:1238Third Party Advisory
- https://helpx.adobe.com/security/products/flash-player/apsa16-03.htmlVendor Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb16-18.htmlVendor Advisory
- https://security.gentoo.org/glsa/201606-08Third Party Advisory
- https://www.kb.cert.org/vuls/id/748992Third Party Advisory, US Government Resource
- https://github.com/cisagov/vulnrichment/issues/196Issue Tracking
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-4171US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.