ZeroHour

CVE-2016-7855

KEVmass

Use-After-Free RCE in Adobe Flash Player (Windows, macOS, Linux)

CISA: Adobe Flash Player Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
25%p98
Published
()
KEV added
AI analysis

Adobe Flash Player for Windows, macOS/OS X, and Linux contains a use-after-free memory flaw (CWE-416) in which memory that has been freed is referenced again, corrupting memory when the player processes attacker-controlled Flash content remotely, typically via a malicious SWF delivered through a browser or another host application. A successful attack allows arbitrary code execution with the privileges of the user running Flash, commonly leading to full workstation compromise in browsing contexts. Anyone still running an affected Adobe Flash Player build is exposed, although the product has been end-of-life since early 2021 and CISA explicitly advises disconnecting or removing it rather than continuing to patch. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added March 3, 2022), confirming known in-the-wild exploitation, and EPSS assigns a 25.2% probability of exploitation within 30 days (98th percentile); no public proof-of-concept is known and ransomware use is unknown.

What to do: Because Flash Player is end-of-life and no longer receives security updates, follow CISA's required action: uninstall or disable Flash everywhere it remains, including browser plugins, standalone installs, and legacy applications that invoke it. If removal must be delayed, ensure the latest patched release from Adobe's security advisories is in place and block or sandbox untrusted Flash content. On systems where Flash is still active, hunt for indicators of compromise given the KEV listing and high EPSS score.

Affected
Adobe Flash Player
Estimated exposure
mass≈1 billion+ installs historically (Flash was near-ubiquitous; residual post-EOL installs unknown) — Adobe publicly reported Flash Player installed on over a billion devices (roughly 99% of internet-connected PCs) during the 2010s, making it one of the most widely deployed browser plugins ever, while the number of lingering installations…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
adoberedhat
Products
flash player, enterprise linux desktop, enterprise linux server, enterprise linux workstation
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news