PT-2016-3359 · Adobe+3 · Flash Player+3

Published

2016-10-26

·

Updated

2025-02-14

·

CVE-2016-7855

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Flash Player versions prior to 23.0.0.205 on Windows and OS X Adobe Flash Player versions prior to 11.2.202.643 on Linux
Description A use-after-free issue in Adobe Flash Player allows remote attackers to execute arbitrary code via unspecified vectors. This issue has been exploited in the wild in October 2016.
Recommendations For Adobe Flash Player versions prior to 23.0.0.205 on Windows and OS X, update to version 23.0.0.205 or later. For Adobe Flash Player versions prior to 11.2.202.643 on Linux, update to version 11.2.202.643 or later. As a temporary workaround, consider disabling Adobe Flash Player until a patch is available.

Fix

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2203
ALT-PU-2016-2204
BDU:2021-05439
CVE-2016-7855
MGASA-2016-0360
OPENSUSE-SU-2016_2663-1
OPENSUSE-SU-2016_2665-1
RHSA-2016:2119
RHSA-2016_2119
SUSE-SU-2016:2662-1
SUSE-SU-2016_2662-1

Affected Products

Alt Linux
Flash Player
Red Hat
Suse