CVE-2016-4171
KEVmassUnspecified Remote Code Execution Flaw in Adobe Flash Player
CISA: Adobe Flash Player Remote Code Execution Vulnerability
CVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player that allows remote code execution; neither the CVE description nor CISA provides technical detail on the underlying flaw. As a Flash RCE, it is presumably triggered by getting a victim to load attacker-supplied Flash content (for example a malicious SWF in a web page or document), though the available data does not confirm the attack vector. Successful exploitation would let an attacker execute arbitrary code with the privileges of the user running Flash, typically yielding a foothold on the endpoint. All Adobe Flash Player deployments are affected per the data, and because Flash reached end-of-life at the end of 2020, anyone still running it is on an unpatched legacy product. The vulnerability is known exploited: CISA added it to the KEV catalog on 2022-03-25 (ransomware use unknown), EPSS assigns a 20.2% probability of exploitation within 30 days (97th percentile), and no public proof-of-concept is known.
What to do: Per CISA's required action, remove or disconnect Adobe Flash Player wherever it is still in use - the product is end-of-life and unpatched, so there is no fixed version to upgrade to. Audit endpoints and internal applications for Flash dependencies (standalone Flash, projector files, legacy intranet apps), migrate or retire them, and as a stopgap block SWF/Flash content at mail and web gateways.
| Adobe Flash Player | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
- Affected
- Adobe Flash Player
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown