CVE-2016-4171 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 20.1% (pctl 97)
Patch first
On CISA KEV — known exploited in the wild, due 2022-04-15.
Description
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 20.06% — more likely to be exploited than 97% of all CVEs |
| On CISA KEV | yes — remediate by 2022-04-15 |
| Public exploit | none known |
| Published | 2016-06-16 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Adobe Flash Player Remote Code Execution Vulnerability |
|---|---|
| Added | 2022-03-25 |
| Due | 2022-04-15 |
| Vendor / product | Adobe / Flash Player |
| Ransomware use | none reported |
Affected (14)
| Vendor | Product |
|---|---|
| adobe | flash player |
| apple | mac os x |
| apple | macos |
| chrome os | |
| linux | linux kernel |
| microsoft | windows |
| microsoft | windows 10 |
| microsoft | windows 8.1 |
| opensuse | opensuse |
| redhat | enterprise linux desktop |
| redhat | enterprise linux server |
| redhat | enterprise linux workstation |
| suse | linux enterprise desktop |
| suse | linux enterprise workstation extension |
References
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html
- http://www.securityfocus.com/bid/91184
- http://www.securitytracker.com/id/1036094
- https://access.redhat.com/errata/RHSA-2016:1238
- https://helpx.adobe.com/security/products/flash-player/apsa16-03.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-18.html
- https://security.gentoo.org/glsa/201606-08
- https://www.kb.cert.org/vuls/id/748992
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html
- http://www.securityfocus.com/bid/91184
- http://www.securitytracker.com/id/1036094
- https://access.redhat.com/errata/RHSA-2016:1238
- https://helpx.adobe.com/security/products/flash-player/apsa16-03.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-18.html
- https://security.gentoo.org/glsa/201606-08
- https://www.kb.cert.org/vuls/id/748992
→ the Explorer · watch your stack · NVD