cbcvebase.
CVE-2016-4117
published 2016-05-11

CVE-2016-4117: Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
94.35%
99.8th percentile
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

Affected

14 ranges
VendorProductVersion rangeFixed in
adobeflash_player<= 21.0.0.226
opensuseevergreen
opensuseopensuse
opensuseopensuse
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_from_rhui
redhatenterprise_linux_server_from_rhui
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
suselinux_enterprise_desktop
suselinux_enterprise_workstation_extension

Detection & IOCsextracted from sources · hover to see the quote

domaineye-watch[.]in
porteye-watch[.]in:443
filenameswf
  • CVE-2016-4117 was leveraged alongside CVE-2015-8651 and CVE-2016-1019 in watering hole attacks; compromised websites redirected victims to a C&C/payload-hosting URL (sap[.]misapor[.]ch) that served the Flash exploits.
  • The exploit campaign delivered RATANKBA (TROJ_RATANKBA.A) as an initial payload via watering hole; defenders should hunt for RATANKBA detections on hosts that visited compromised financial-sector websites.
  • Post-exploitation tooling included nbt_scan.exe (HKTL_NBTSCAN.GA / HKTL_NBTSCAN.GB), a NetBIOS scanner used for lateral movement; presence of this tool on a host is a strong indicator of compromise in this campaign.
  • The attack chain also dropped BKDR_DESTOVER.ADU (information-stealing backdoor) and a Silverlight exploit (CVE-2016-0034) packaged as Shell_siver.dll (TROJ_CVE20130074.B); detection of these files indicates full compromise.
  • Adobe Flash Player versions 21.0.0.226 and earlier are vulnerable; patch APSB16-15 (released May 12, 2016) addresses CVE-2016-4117. Detect unpatched Flash versions in the environment as a risk indicator.
  • ·The domains eye-watch[.]in and sap[.]misapor[.]ch were identified as compromised legitimate sites used as C&C/payload hosts, not attacker-owned infrastructure; blocking them may affect legitimate services.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.