CVE-2016-7892
HIGH KEVAdobe Flash Player Desktop Runtime < 23.0.0.207 - Use After Free
Title source: ruleDescription
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.
References (9)
Scores
CVSS v3
8.8
EPSS
0.2015
EPSS Percentile
95.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-03-25
VulnCheck KEV
2016-12-13
InTheWild.io
2016-12-13
ENISA EUVD
EUVD-2016-8741
CWE
CWE-416
Status
published
Products (4)
adobe/flash_player
< 11.2.202.644
adobe/flash_player
< 23.0.0.207 (3 CPE variants)
adobe/flash_player_desktop_runtime
< 23.0.0.207
n/a/Adobe Flash Player 23.0.0.207 and earlier, 11.2.202.644 and earlier
Adobe Flash Player 23.0.0.207 and earlier, 11.2.202.644 and earlier
Published
Dec 15, 2016
KEV Added
Mar 25, 2022
Tracked Since
Feb 18, 2026