peter bassill · operator
$ cve CVE-2016-4171 JSON

CVE-2016-4171 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 20.1% (pctl 97)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-15.

Description

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS20.06% — more likely to be exploited than 97% of all CVEs
On CISA KEVyes — remediate by 2022-04-15
Public exploitnone known
Published2016-06-16
Last modified2026-06-17

CISA KEV

NameAdobe Flash Player Remote Code Execution Vulnerability
Added2022-03-25
Due2022-04-15
Vendor / productAdobe / Flash Player
Ransomware usenone reported

Affected (14)

VendorProduct
adobeflash player
applemac os x
applemacos
googlechrome os
linuxlinux kernel
microsoftwindows
microsoftwindows 10
microsoftwindows 8.1
opensuseopensuse
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux workstation
suselinux enterprise desktop
suselinux enterprise workstation extension

References

→ the Explorer  ·  watch your stack  ·  NVD