Junglewise Threat Intelligence

CVE-2016-7855: Adobe Flash Player Use-After-Free Vulnerability

CVE-2016-7855 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-03

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

A use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code via unspecified vectors. The vulnerability was exploited in the wild in October 2016 and affects versions on Windows, OS X, and Linux.

Affected products

  • Adobe Systems Incorporated Flash Player before 23.0.0.205 on Windows and OS X; before 11.2.202.643 on Linux

Timeline

  • 2016-10: exploited: Exploited in the wild in October 2016.
  • 2016-10-26: advisory: Adobe released security bulletin APSB16-36.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats