peter bassill · operator
$ cve CVE-2016-7892 JSON

CVE-2016-7892 KEV

8.8
HIGH · CVSS 3.1 · EPSS 18.8% (pctl 97)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-15.

Description

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS18.79% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-416
On CISA KEVyes — remediate by 2022-04-15
Public exploitnone known
Published2016-12-15
Last modified2026-06-17

CISA KEV

NameAdobe Flash Player Use-After-Free Vulnerability
Added2022-03-25
Due2022-04-15
Vendor / productAdobe / Flash Player
Ransomware usenone reported

Affected (8)

VendorProduct
adobeflash player
adobeflash player desktop runtime
applemac os x
googlechrome os
linuxlinux kernel
microsoftwindows
microsoftwindows 10
microsoftwindows 8.1

References

→ the Explorer  ·  watch your stack  ·  NVD