Junglewise Threat Intelligence

CVE-2016-4171: Adobe Flash Player Remote Code Execution Vulnerability

CVE-2016-4171 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

An unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code. The vulnerability was reported to be exploited in the wild prior to its formal cataloging in the CISA KEV.

Affected products

  • Adobe Flash Player 21.0.0.242 and earlier

Timeline

  • 2016-06-01: exploited: Exploited in the wild in June 2016.
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats