← All CVEs

CVE-2016-7892

high · 8.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

The impacted product is end-of-life and should be disconnected if still in use.

Added 2022-03-25Remediation due 2022-04-15

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

8.8
CVSS
18.8%
EPSS (exploit prob.)
97th
EPSS percentile
2016-12-15
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-416

Affected products

VendorProductAffected versions
adobeflash_player_desktop_runtime<= 23.0.0.207
applemac_os_xall versions
microsoftwindowsall versions
adobeflash_player<= 23.0.0.207
adobeflash_player<= 23.0.0.207
microsoftwindows_10all versions
microsoftwindows_8.1all versions
adobeflash_player<= 23.0.0.207
applemac_os_xall versions
googlechrome_osall versions
linuxlinux_kernelall versions
microsoftwindowsall versions
adobeflash_player<= 11.2.202.644
linuxlinux_kernelall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-7892