CVE-2016-4171

Published Jun 16, 2016

Last updated 3 years ago

Overview

Description
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
Source
psirt@adobe.com
NVD status
Analyzed

Social media

Hype score
Not currently trending

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

CVSS 2.0

Type
Primary
Base score
10
Impact score
10
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:C/I:C/A:C

Known exploits

Data from CISA

Vulnerability name
Adobe Flash Player Remote Code Execution Vulnerability
Exploit added on
Mar 25, 2022
Exploit action due
Apr 15, 2022
Required action
The impacted product is end-of-life and should be disconnected if still in use.

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo

Configurations