CVE-2016-4117
KEV ransomware PoC massArbitrary Code Execution in Adobe Flash Player 21.0.0.226 and earlier
CISA: Adobe Flash Player Arbitrary Code Execution Vulnerability
CVE-2016-4117 is a critical (CVSS 3.1: 9.8) arbitrary code execution vulnerability in Adobe Flash Player 21.0.0.226 and earlier, in which unspecified vectors in the Flash runtime allow remote attackers to execute arbitrary code. It is triggered by delivering malicious Flash content over a network — for example a crafted SWF loaded by a browser or an application that embeds Flash — and, per its CVSS scoring, requires no privileges or authentication. A successful exploit gives the attacker code execution in the context of the Flash runtime (typically the user's browser process), which public reporting shows was used to deliver espionage tooling and, per CISA, is also known to be used in ransomware campaigns. Anyone running Flash Player 21.0.0.226 or earlier was affected, including users of the flash-player packages shipped for Red Hat Enterprise Linux Desktop, Server (including the RHUI variant) and Workstation, openSUSE, openSUSE Evergreen, and SUSE Linux Enterprise Desktop and the SUSE Linux Enterprise Workstation Extension. The bug was exploited in the wild in May 2016 — related headlines tie it to the BlackOasis APT 'Operation Daybreak' espionage campaign using FinFisher — and it was added to the CISA KEV on 2022-03-03 with known ransomware use and a very high 94.4% EPSS.
What to do: Per CISA's required action, Flash Player is end-of-life: remove or disable Flash wherever it is still present and uninstall the flash-player packages on any remaining RHEL, SUSE or openSUSE hosts, especially internet-facing systems. If a legacy system must keep Flash, ensure it runs a release later than 21.0.0.226 (a fixed build from the May 2016 Adobe update or later) and restrict it from untrusted web content.
| adobe Flash Player | 21.0.0.226 and earlier (all editions) |
| redhat Enterprise Linux Desktop (flash-player package) | — |
| redhat Enterprise Linux Server (flash-player package) | — |
| redhat Enterprise Linux Server from RHUI (flash-player package) | — |
| redhat Enterprise Linux Workstation (flash-player package) | — |
| openSUSE Evergreen (flash-player package) | — |
| openSUSE (flash-player package) | — |
| suse Linux Enterprise Desktop (flash-player package) | — |
| suse Linux Enterprise Workstation Extension (flash-player package) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
- Affected
- Adobe Flash Player
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Known
- Vendors
- adoberedhatopensusesuse
- Products
- flash player, enterprise linux desktop, enterprise linux server, enterprise linux server from rhui, enterprise linux workstation, evergreen, opensuse, linux enterprise desktop, linux enterprise workstation extension
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H