CVE-2016-7892

HIGH KEV

Adobe Flash Player Desktop Runtime < 23.0.0.207 - Use After Free

Title source: rule

Description

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

Scores

CVSS v3 8.8
EPSS 0.2015
EPSS Percentile 95.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-03-25
VulnCheck KEV 2016-12-13
InTheWild.io 2016-12-13
ENISA EUVD EUVD-2016-8741
CWE
CWE-416
Status published
Products (4)
adobe/flash_player < 11.2.202.644
adobe/flash_player < 23.0.0.207 (3 CPE variants)
adobe/flash_player_desktop_runtime < 23.0.0.207
n/a/Adobe Flash Player 23.0.0.207 and earlier, 11.2.202.644 and earlier Adobe Flash Player 23.0.0.207 and earlier, 11.2.202.644 and earlier
Published Dec 15, 2016
KEV Added Mar 25, 2022
Tracked Since Feb 18, 2026