Arbitrary Code Execution Vulnerability in Adobe Flash Player on Windows, OS X, and Linux
CVE-2016-4177
8.8HIGH
Summary
Adobe Flash Player prior to version 18.0.0.366 on Windows, versions 19.x through 22.x prior to 22.0.0.209 on Windows and OS X, and versions before 11.2.202.632 on Linux is vulnerable to an attack that can execute arbitrary code or lead to a denial of service due to stack memory corruption through unspecified vectors. It is crucial for users to update their Flash Player to mitigate this risk.
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved