Type Confusion Vulnerability in Adobe Flash Player
CVE-2016-7865
8.8HIGH
Key Information:
- Vendor
- Adobe
- Vendor
- CVE Published:
- 8 November 2016
Summary
Adobe Flash Player is susceptible to a type confusion vulnerability that affects multiple versions, allowing attackers to potentially execute arbitrary code. This issue arises due to incorrect handling of object types, leading to exploitable conditions. If successfully exploited, it can compromise system security, making mitigation through updates crucial. Users are urged to upgrade to the latest versions to mitigate risks.
Affected Version(s)
Adobe Flash Player 23.0.0.205 and earlier, 11.2.202.643 and earlier Adobe Flash Player 23.0.0.205 and earlier, 11.2.202.643 and earlier
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved