peter bassill · operator
$ cve CVE-2016-4117 JSON

CVE-2016-4117 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 94.4% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-24.

Description

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS94.35% — more likely to be exploited than 100% of all CVEs
On CISA KEVyes — remediate by 2022-03-24
Public exploityes
Published2016-05-11
Last modified2026-09-10

CISA KEV

NameAdobe Flash Player Arbitrary Code Execution Vulnerability
Added2022-03-03
Due2022-03-24
Vendor / productAdobe / Flash Player
Ransomware useknown

Affected (9)

VendorProduct
adobeflash player
opensuseevergreen
opensuseopensuse
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server from rhui
redhatenterprise linux workstation
suselinux enterprise desktop
suselinux enterprise workstation extension

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD