Executive brief
Adobe Flash Player contains a use-after-free vulnerability in the TextField class. Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the target system, typically requiring user interaction such as visiting a malicious website.
Affected products
- Adobe Systems Incorporated Flash Player 23.0.0.207 and earlier
- Adobe Systems Incorporated Flash Player 11.2.202.644 and earlier
Timeline
- 2016-12-13: advisory: Original Adobe advisory APSB16-39 published
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-25: disclosed: NVD publication date