Arbitrary Code Execution Vulnerability in Adobe Flash Player on Windows, OS X, and Linux
CVE-2016-4177

8.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
13 July 2016

Summary

Adobe Flash Player prior to version 18.0.0.366 on Windows, versions 19.x through 22.x prior to 22.0.0.209 on Windows and OS X, and versions before 11.2.202.632 on Linux is vulnerable to an attack that can execute arbitrary code or lead to a denial of service due to stack memory corruption through unspecified vectors. It is crucial for users to update their Flash Player to mitigate this risk.

References

EPSS Score

11% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.