CVE-2016-7892

HIGH KEV

Adobe Flash Player < 23.0.0.207 and <= 11.2.202.644 - Use-After-Free in TextField Class

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2016-7892 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 25, 2022.

Description

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

References (9)

Core 9
Core References
Patch, Third Party Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-154
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201701-17
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037442
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-2947.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94877
Broken Link vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2016-12/msg00112.html

Scores

CVSS v3 8.8
EPSS 0.2197
EPSS Percentile 95.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-03-25
VulnCheck KEV 2016-12-13
InTheWild.io 2016-12-13
ENISA EUVD EUVD-2016-8741
CWE
CWE-416
Status published
Products (4)
adobe/flash_player < 11.2.202.644
adobe/flash_player < 23.0.0.207 (3 CPE variants)
adobe/flash_player_desktop_runtime < 23.0.0.207
n/a/Adobe Flash Player 23.0.0.207 and earlier, 11.2.202.644 and earlier Adobe Flash Player 23.0.0.207 and earlier, 11.2.202.644 and earlier
Published Dec 15, 2016
KEV Added Mar 25, 2022
Tracked Since Feb 18, 2026