Use-After-Free Vulnerability in Adobe Flash Player Affecting Multiple Versions
CVE-2016-7857
8.8HIGH
Key Information:
- Vendor
- Adobe
- Vendor
- CVE Published:
- 8 November 2016
Summary
Adobe Flash Player versions 23.0.0.205 and prior, along with version 11.2.202.643 and earlier, are susceptible to a use-after-free vulnerability. This flaw allows an attacker to exploit the memory management and gain the capability to execute arbitrary code on an affected system, potentially compromising user data and system integrity.
Affected Version(s)
Adobe Flash Player 23.0.0.205 and earlier, 11.2.202.643 and earlier Adobe Flash Player 23.0.0.205 and earlier, 11.2.202.643 and earlier
References
EPSS Score
9% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved