CVE-2016-7855
Last modified
CVE-2016-7855 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.. CISA has confirmed active exploitation in the wild. EPSS estimates a 25.20% chance of exploitation in the next 30 days.
Description
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Flash Player | <= 23.0.0.185 |
| Adobe | Flash Player | <= 11.2.202.637 |
| Redhat | Enterprise Linux Desktop | 5.0 |
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Server | 5.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Workstation | 5.0 |
| Redhat | Enterprise Linux Workstation | 6.0 |
References
- http://rhn.redhat.com/errata/RHSA-2016-2119.htmlThird Party Advisory
- http://www.securityfocus.com/bid/93861Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037111Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-128Patch, Vendor Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb16-36.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/201610-10Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2119.htmlThird Party Advisory
- http://www.securityfocus.com/bid/93861Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037111Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-128Patch, Vendor Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb16-36.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/201610-10Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-7855US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2016-7855?
How severe is CVE-2016-7855?
How do I fix CVE-2016-7855?
Are you affected by CVE-2016-7855?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
