CVE-2016-7855
Last modified
CVE-2016-7855 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.. CISA has confirmed active exploitation in the wild. EPSS estimates a 25.20% chance of exploitation in the next 30 days.
Description
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Flash Player | <= 23.0.0.185 |
| Adobe | Flash Player | <= 11.2.202.637 |
| Redhat | Enterprise Linux Desktop | 5.0 |
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Server | 5.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Workstation | 5.0 |
| Redhat | Enterprise Linux Workstation | 6.0 |
References
- http://rhn.redhat.com/errata/RHSA-2016-2119.htmlThird Party Advisory
- http://www.securityfocus.com/bid/93861Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037111Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-128Patch, Vendor Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb16-36.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/201610-10Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2119.htmlThird Party Advisory
- http://www.securityfocus.com/bid/93861Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037111Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-128Patch, Vendor Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb16-36.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/201610-10Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-7855US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2016-7855?
How severe is CVE-2016-7855?
How do I fix CVE-2016-7855?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-7849Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-7850Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-7851Adobe Connect version 9.5.6 and earlier does not adequately …
- CVE-2016-7852Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat…
- CVE-2016-7853Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat…
- CVE-2016-7854Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat…
- CVE-2016-7856Adobe DNG Converter versions 9.7 and earlier have an exploit…
- CVE-2016-7857Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202…
- CVE-2016-7858Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202…
- CVE-2016-7859Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202…
- CVE-2016-7860Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202…
- CVE-2016-7861Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202…
Are you affected by CVE-2016-7855?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
