Junglewise Threat Intelligence

CVE-2016-7892: Adobe Flash Player Use-After-Free Vulnerability

CVE-2016-7892 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-25

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Flash Player contains a use-after-free vulnerability in the TextField class. Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the target system, typically requiring user interaction such as visiting a malicious website.

Affected products

  • Adobe Systems Incorporated Flash Player 23.0.0.207 and earlier
  • Adobe Systems Incorporated Flash Player 11.2.202.644 and earlier

Timeline

  • 2016-12-13: advisory: Original Adobe advisory APSB16-39 published
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-25: disclosed: NVD publication date

Related threats