Arbitrary Code Execution and Denial of Service in Adobe Flash Player
CVE-2016-4186

8.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
13 July 2016

What is CVE-2016-4186?

Adobe Flash Player versions prior to 18.0.0.366 for Windows, 19.x through 22.x before 22.0.0.209 for OS X, and before 11.2.202.632 for Linux are susceptible to a vulnerability that can be exploited by attackers to execute arbitrary code or cause a denial of service condition. This occurs via unspecified vectors and represents a significant risk, differing from related vulnerabilities within the same release lifecycle. Users of affected versions are urged to upgrade to the latest version to mitigate these risks.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.