ZeroHour

CVE-2016-7892

KEVmass

Use-After-Free RCE in Adobe Flash Player TextField (CVE-2016-7892)

CISA: Adobe Flash Player Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
19%p97
Published
()
KEV added
AI analysis

CVE-2016-7892 is a use-after-free memory-corruption flaw (CWE-416) in the TextField class of Adobe Flash Player. An attacker triggers it by convincing a user to open malicious Flash (SWF) content, typically embedded in a web page or delivered document; the CVSS vector (AV:N/AC:L/PR:N/UI:R) confirms exploitation requires network access and user interaction but no privileges. Successful exploitation yields arbitrary code execution with the victim user's privileges (CVSS 3.1: 8.8 High). Anyone running affected Flash versions is affected — Adobe Flash Player Desktop Runtime 23.0.0.207 and earlier, and the 11.2.202.644-and-earlier Linux line — with the practical risk concentrated on any systems still executing Flash content today. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), indicating known in-the-wild exploitation; no public proof-of-concept is known, ransomware use is unknown, and EPSS is 18.8% (97th percentile).

What to do: Update Flash Player to a version later than 23.0.0.207 (desktop) or 11.2.202.644 (Linux) via the December 2016 Adobe security update — or, preferably, since Flash is end-of-life per CISA, uninstall or disable Flash and stop rendering SWF content entirely. Inventory any systems still invoking Flash (legacy browser plugins, embedded or enterprise applications that render Flash content) and retire or disconnect them, as CISA's required action directs. Because exploitation requires user interaction, blocking untrusted Flash content and email-delivered SWF files further reduces risk.

Affected
Adobe Flash Player Desktop Runtime23.0.0.207 and earlier
Adobe Flash Player (Linux 11.2.x extended support line)11.2.202.644 and earlier
Estimated exposure
mass≈1 billion+ installs at disclosure (Flash ran on roughly 99% of internet-connected PCs in 2016); current active footprint unknown and much smaller post-EOL — Adobe Flash was near-universally installed on internet-connected desktops when this flaw was disclosed, giving an order-of-magnitude of a billion-plus devices, but the browser plugin was retired at end-of-life, so the number of systems…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
adobe
Products
flash player desktop runtime, flash player
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news