CVE-2016-7892 KEV
8.8
HIGH · CVSS 3.1 · EPSS 18.8% (pctl 97)
Patch first
On CISA KEV — known exploited in the wild, due 2022-04-15.
Description
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 18.79% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-416 |
| On CISA KEV | yes — remediate by 2022-04-15 |
| Public exploit | none known |
| Published | 2016-12-15 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Adobe Flash Player Use-After-Free Vulnerability |
|---|---|
| Added | 2022-03-25 |
| Due | 2022-04-15 |
| Vendor / product | Adobe / Flash Player |
| Ransomware use | none reported |
Affected (8)
| Vendor | Product |
|---|---|
| adobe | flash player |
| adobe | flash player desktop runtime |
| apple | mac os x |
| chrome os | |
| linux | linux kernel |
| microsoft | windows |
| microsoft | windows 10 |
| microsoft | windows 8.1 |
References
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00064.html
- http://lists.opensuse.org/opensuse-updates/2016-12/msg00112.html
- http://rhn.redhat.com/errata/RHSA-2016-2947.html
- http://www.securityfocus.com/bid/94877
- http://www.securitytracker.com/id/1037442
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-154
- https://helpx.adobe.com/security/products/flash-player/apsb16-39.html
- https://security.gentoo.org/glsa/201701-17
- http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00064.html
- http://lists.opensuse.org/opensuse-updates/2016-12/msg00112.html
- http://rhn.redhat.com/errata/RHSA-2016-2947.html
- http://www.securityfocus.com/bid/94877
- http://www.securitytracker.com/id/1037442
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-154
- https://helpx.adobe.com/security/products/flash-player/apsb16-39.html
- https://security.gentoo.org/glsa/201701-17
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-7892
→ the Explorer · watch your stack · NVD