SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2016-4171

Adobe Flash Player Remote Code Execution Vulnerability

KEVCRITICAL 9.8EPSS 20.2%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
20.21% probability · 97th percentile
CISA KEV
Listed 25 March 2022 · due 15 April 2022
Affected
adobe/flash player · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise workstation extension
Source
psirt@adobe.com

CISA notes

The impacted product is end-of-life and should be disconnected if still in use. https://nvd.nist.gov/vuln/detail/CVE-2016-4171

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.