CVE-2016-7855

HIGH KEV

Adobe Flash Player < 23.0.0.205 - Use-After-Free

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2016-7855 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 3, 2022. EIP tracks 1 public exploit from researchers including swagatbora90.

AI-analyzed exploit summary This repository contains a tool to detect the Flash Player version in a browser to check for vulnerability to CVE-2016-7855. It uses SWFObject to identify the Flash Player version but does not include exploit code.

Description

Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.

Exploits (1)

nomisec SCANNER 1 stars
by swagatbora90 · poc
https://github.com/swagatbora90/CheckFlashPlayerVersion

This repository contains a tool to detect the Flash Player version in a browser to check for vulnerability to CVE-2016-7855. It uses SWFObject to identify the Flash Player version but does not include exploit code.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Adobe Flash Player
No auth needed
Prerequisites: Browser with Flash Player installed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201610-10
Patch, Vendor Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-128
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037111
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-2119.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93861

Scores

CVSS v3 8.8
EPSS 0.2520
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-03-03
VulnCheck KEV 2016-10-21
InTheWild.io 2016-10-21
ENISA EUVD EUVD-2016-8704
CWE
CWE-416
Status published
Products (8)
adobe/flash_player < 11.2.202.637
adobe/flash_player < 23.0.0.185 (4 CPE variants)
redhat/enterprise_linux_desktop 5.0
redhat/enterprise_linux_desktop 6.0
redhat/enterprise_linux_server 5.0
redhat/enterprise_linux_server 6.0
redhat/enterprise_linux_workstation 5.0
redhat/enterprise_linux_workstation 6.0
Published Nov 01, 2016
KEV Added Mar 03, 2022
Tracked Since Feb 18, 2026