Junglewise Threat Intelligence

CVE-2016-4117: Adobe Flash Player Arbitrary Code Execution Vulnerability

CVE-2016-4117 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-03

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Flash Player 21.0.0.226 and earlier contains an access of resource using incompatible type vulnerability. This flaw allows remote attackers to execute arbitrary code via unspecified vectors.

Affected products

  • Adobe Flash Player 21.0.0.226 and earlier

Timeline

  • 2016-05: exploited: Exploited in the wild in May 2016.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats