CVE-2016-4117
published 2016-05-11CVE-2016-4117: Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
94.35%
99.8th percentile
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 21.0.0.226 | — |
| opensuse | evergreen | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_from_rhui | — | — |
| redhat | enterprise_linux_server_from_rhui | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_workstation_extension | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2016-4117 was leveraged alongside CVE-2015-8651 and CVE-2016-1019 in watering hole attacks; compromised websites redirected victims to a C&C/payload-hosting URL (sap[.]misapor[.]ch) that served the Flash exploits. ↗
- →The exploit campaign delivered RATANKBA (TROJ_RATANKBA.A) as an initial payload via watering hole; defenders should hunt for RATANKBA detections on hosts that visited compromised financial-sector websites. ↗
- →Post-exploitation tooling included nbt_scan.exe (HKTL_NBTSCAN.GA / HKTL_NBTSCAN.GB), a NetBIOS scanner used for lateral movement; presence of this tool on a host is a strong indicator of compromise in this campaign. ↗
- →The attack chain also dropped BKDR_DESTOVER.ADU (information-stealing backdoor) and a Silverlight exploit (CVE-2016-0034) packaged as Shell_siver.dll (TROJ_CVE20130074.B); detection of these files indicates full compromise. ↗
- →Adobe Flash Player versions 21.0.0.226 and earlier are vulnerable; patch APSB16-15 (released May 12, 2016) addresses CVE-2016-4117. Detect unpatched Flash versions in the environment as a risk indicator. ↗
- ·The domains eye-watch[.]in and sap[.]misapor[.]ch were identified as compromised legitimate sites used as C&C/payload hosts, not attacker-owned infrastructure; blocking them may affect legitimate services. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Flash Player up to 21.0.0.226 memory corruption (RHSA-2016:1079 / EDB-46339)
vuldb·2026-04-23·CVSS 9.8
CVE-2016-4117 [CRITICAL] Adobe Flash Player up to 21.0.0.226 memory corruption (RHSA-2016:1079 / EDB-46339)
A vulnerability identified as critical has been detected in Adobe Flash Player up to 21.0.0.226. This impacts an unknown function. The manipulation leads to memory corruption.
This vulnerability is listed as CVE-2016-4117. The attack may be initiated remotely. In addition, an exploit is available.
You should upgrade the affected component.
GHSA
GHSA-pg3m-fww2-6vrj: Adobe Flash Player 21
ghsa_unreviewed·2022-05-14
CVE-2016-4117 [CRITICAL] GHSA-pg3m-fww2-6vrj: Adobe Flash Player 21
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
OSV
CVE-2016-4117: Adobe Flash Player 21
osv·2016-05-11·CVSS 9.8
CVE-2016-4117 [CRITICAL] CVE-2016-4117: Adobe Flash Player 21
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
VulnCheck
Adobe Flash Player Arbitrary Code Execution Vulnerability
vulncheck·2016·CVSS 9.8
CVE-2016-4117 [CRITICAL] Adobe Flash Player Arbitrary Code Execution Vulnerability
Adobe Flash Player Arbitrary Code Execution Vulnerability
An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.
Affected: Adobe Flash Player
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Known Ransomware Campaign Use: Known
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cve.org/CVERecord?id=CVE-2016-4117; https://security.berkeley.edu/news/vulnerable-adobe-flash-player-allows-remote-code-execution-cve-2016-4117; https://securelist.com/cve-2016-4171-adobe-flash-zero-day-used-in-targeted-attacks/75082/; https://securelist.com/operation-daybreak/75100/; https://ww
CISA
Adobe Flash Player Arbitrary Code Execution Vulnerability
cisa·2022-03-03·CVSS 9.8
CVE-2016-4117 [CRITICAL] Adobe Flash Player Arbitrary Code Execution Vulnerability
Vulnerability: Adobe Flash Player Arbitrary Code Execution Vulnerability
Affected: Adobe Flash Player
An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-4117
Remediation Due Date: 2022-03-24
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-15
vendor_redhat·2016-05-10·CVSS 9.8
CVE-2016-4117 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB16-15
flash-plugin: multiple code execution issues fixed in APSB16-15
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
No detection rules found.
Exploit-DB
Adobe Flash Player - DeleteRangeTimelineOperation Type Confusion (Metasploit)
exploitdb·2019-02-11
CVE-2016-4117 Adobe Flash Player - DeleteRangeTimelineOperation Type Confusion (Metasploit)
Adobe Flash Player - DeleteRangeTimelineOperation Type Confusion (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Adobe Flash Player DeleteRangeTimelineOperation Type-Confusion',
'Description' => %q(
This module exploits a type confusion on Adobe Flash Player, which was
originally found being successfully exploited in the wild. This module
has been tested successfully on:
macOS Sierra 10.12.3,
Safari and Adobe Flash Player 21.0.0.182,
Firefox and Adobe Flash Player 21.0.0.182.
),
'License' => MSF_LICENSE,
'Author' =>
[
'Genwei Jiang', # FireEye original blog details on the vulnerability
'bcook-r7' # Imported Metasploit module
],
'References' =>
[
['CVE', '201
Metasploit
Adobe Flash Player DeleteRangeTimelineOperation Type-Confusion
metasploit
Adobe Flash Player DeleteRangeTimelineOperation Type-Confusion
Adobe Flash Player DeleteRangeTimelineOperation Type-Confusion
This module exploits a type confusion on Adobe Flash Player, which was originally found being successfully exploited in the wild. This module has been tested successfully on: macOS Sierra 10.12.3, Safari and Adobe Flash Player 21.0.0.182, Firefox and Adobe Flash Player 21.0.0.182.
Securelist
APT Trends Report Q2 2018
blogs_securelist·2018-07-10
APT Trends Report Q2 2018
Authors
- GReAT
In the second quarter of 2017, Kaspersky Lab’s Global Research and Analysis Team (GReAT) began publishing summaries of the quarter’s private threat intelligence reports, in an effort to make the public aware of the research we have been conducting. This report serves as the latest installment, focusing on the relevant activities that we observed during Q2 2018.
These summaries are a representative snapshot of what has been discussed in greater detail in our private reports. They aim to highlight the significant events and findings that we feel people should be aware of. For brevity’s sake, we are choosing not to publish indicators associated with the reports highlighted. However, readers who would like to learn more about our intelligence reports or request more informat
Securelist
APT Trends Report Q2 2018
blogs_securelist·2018-07-10
APT Trends Report Q2 2018
Authors
GReAT
In the second quarter of 2017, Kaspersky Lab’s Global Research and Analysis Team (GReAT) began publishing summaries of the quarter’s private threat intelligence reports, in an effort to make the public aware of the research we have been conducting. This report serves as the latest installment, focusing on the relevant activities that we observed during Q2 2018.
These summaries are a representative snapshot of what has been discussed in greater detail in our private reports. They aim to highlight the significant events and findings that we feel people should be aware of. For brevity’s sake, we are choosing not to publish indicators associated with the reports highlighted. However, readers who would like to learn more about our intelligence reports or request more informatio
Securelist
BlackOasis APT and new targeted attacks leveraging zero-day exploit
blogs_securelist·2017-10-16·CVSS 9.8
CVE-2017-11292 [CRITICAL] BlackOasis APT and new targeted attacks leveraging zero-day exploit
Table of Contents
- Introduction
- BlackOasis Background
- Attacks Leveraging CVE-2017-11292
- Targeting and Victims
- Conclusions
- Acknowledgements
- References
- Indicators of compromise
Authors
- GReAT
More information about BlackOasis APT is available to customers of Kaspersky Intelligence Reporting Service. Contact: [email protected]
## Introduction
Kaspersky Lab has always worked closely with vendors to protect users. As soon as we find new vulnerabilities we immediately inform the vendor in a responsible manner and provide all the details required for a fix.
On October 10, 2017, Kaspersky Lab’s advanced exploit prevention systems identified a new Adobe Flash zero day exploit used in the wild against our customers. The exploit was delivered through a Microsoft Offic
Securelist
BlackOasis APT and new targeted attacks leveraging zero-day exploit
blogs_securelist·2017-10-16·CVSS 9.8
CVE-2017-11292 [CRITICAL] BlackOasis APT and new targeted attacks leveraging zero-day exploit
Table of Contents
Introduction
BlackOasis Background
Attacks Leveraging CVE-2017-11292
Payload – mo.exe
Targeting and Victims
Conclusions
Acknowledgements
References
Indicators of compromise
Authors
GReAT
More information about BlackOasis APT is available to customers of Kaspersky Intelligence Reporting Service. Contact: [email protected]
## Introduction
Kaspersky Lab has always worked closely with vendors to protect users. As soon as we find new vulnerabilities we immediately inform the vendor in a responsible manner and provide all the details required for a fix.
On October 10, 2017, Kaspersky Lab’s advanced exploit prevention systems identified a new Adobe Flash zero day exploit used in the wild against our customers. The exploit was delivered through a Microsoft
Securelist
APT Trends report Q2 2017
blogs_securelist·2017-08-08
APT Trends report Q2 2017
Table of Contents
- Introduction
- Russian-Speaking Actors
- English-Speaking Actors
- Korean-speaking Actors
- Middle Eastern Actors
- Chinese-Speaking Actors
- Best of the rest
- Predictions
- How to keep yourself protected
Authors
- GReAT
## Introduction
Since 2014, Kaspersky Lab’s Global Research and Analysis Team (GReAT) has been providing threat intelligence reports to a wide-range of customers worldwide, leading to the delivery of a full and dedicated private reporting service. Prior to the new service offering, GReAT published research online for the general public in an effort to help combat the ever-increasing threat from nation-state and other advanced actors. Since we began offering a threat intelligence service, all deep technical details on advanced campaigns are first
Securelist
APT Trends report Q2 2017
blogs_securelist·2017-08-08·CVSS 7.8
[HIGH] APT Trends report Q2 2017
Table of Contents
Introduction
Russian-Speaking Actors
English-Speaking Actors
Korean-speaking Actors
Middle Eastern Actors
Chinese-Speaking Actors
Best of the rest
Predictions
How to keep yourself protected
Authors
GReAT
## Introduction
Kaspersky’s Private Threat Intelligence Portal (TIP)
In Q1 of 2017 we published our first APT Trends report , highlighting our top research findings over the last few months. We will continue to publish quarterly reports as a representative snapshot of what has been offered in greater detail in our private reports in order to highlight significant events and findings we feel most users should be aware of. If you would like to learn more about our intelligence reports or request more information for a specific report, readers are encouraged to
Trendmicro
RATANKBA: Delving into Large-scale Watering Holes
blogs_trendmicro·2017-02-27
RATANKBA: Delving into Large-scale Watering Holes
Malware
## RATANKBA: Delving into Large-scale Watering Holes
We provide further analysis and insights regarding the RATANKBA malware, which was tied to malware attacks against banks in Poland, but also in a string of similar incidents involving financial institutions in different countries.
By: Trend Micro 2017/02/27 Read time: ( words)
Save to Folio
In early February, several financial organizations reported malware infection on their workstations, apparently coming from legitimate websites. The attacks turned out to be part of a large-scale campaign to compromise trusted websites in order to infect the systems of targeted enterprises across various industries. The strategy is typically known as a “ watering hole ” attack.
It was all sparked by a spate of recent malware attacks on P
Trendmicro
RATANKBA: Delving into Large-scale Watering Holes
blogs_trendmicro·2017-02-27
RATANKBA: Delving into Large-scale Watering Holes
Malware
# RATANKBA: Delving into Large-scale Watering Holes
We provide further analysis and insights regarding the RATANKBA malware, which was tied to malware attacks against banks in Poland, but also in a string of similar incidents involving financial institutions in different countries.
By: Trend Micro
2017/02/27
Read time: ( words)
Save to Folio
In early February, several financial organizations reported malware infection on their workstations, apparently coming from legitimate websites. The attacks turned out to be part of a large-scale campaign to compromise trusted websites in order to infect the systems of targeted enterprises across various industries. The strategy is typically known as a “watering hole” attack.
It was all sparked by a spate of recent malware attacks on Pol
Trendmicro
RATANKBA: Delving into Large-scale Watering Holes
blogs_trendmicro·2017-02-27
RATANKBA: Delving into Large-scale Watering Holes
Malware
## RATANKBA: Delving into Large-scale Watering Holes
We provide further analysis and insights regarding the RATANKBA malware, which was tied to malware attacks against banks in Poland, but also in a string of similar incidents involving financial institutions in different countries.
By: Trend Micro Feb 27, 2017 Read time: ( words)
Save to Folio
In early February, several financial organizations reported malware infection on their workstations, apparently coming from legitimate websites. The attacks turned out to be part of a large-scale campaign to compromise trusted websites in order to infect the systems of targeted enterprises across various industries. The strategy is typically known as a “ watering hole ” attack.
It was all sparked by a spate of recent malware attacks on
Securelist
IT threat evolution in Q2 2016. Statistics
blogs_securelist·2016-08-11
IT threat evolution in Q2 2016. Statistics
Table of Contents
- Q2 figures
- Mobile threats
- Vulnerable applications exploited by cybercriminals
- Online threats (Web-based attacks)
Authors
- Roman Unuchek
- Maria Garnaeva
- Anton Ivanov
- Denis Makrushin
- Fedor Sinitsyn
Download the full report (PDF)
All the statistics used in this report were obtained using Kaspersky Security Network (KSN), a distributed antivirus network that works with various anti-malware protection components. The data was collected from KSN users who agreed to provide it. Millions of Kaspersky Lab product users from 213 countries and territories worldwide participate in this global exchange of information about malicious activity.
## Q2 figures
- According to KSN data, Kaspersky Lab solutions detected and repelled 171,895,830 malicious attacks from o
Qualys
Update: Patch Tuesday May 2016 | Qualys
blogs_qualys·2016-05-12·CVSS 7.5
CVE-2016-4117 [HIGH] Update: Patch Tuesday May 2016 | Qualys
Update: Adobe released the patch for Adobe Flash that addresses the current 0-day CVE-2016-4117 in APSB16-15. It also patches another 24 vulnerabilities that are mostly rated critical. Patch as quickly as possible. Chrome and Internet Explorer 11/Edge users will get their patches from Google and Microsoft automatically.
Original: Today is the second Tuesday of the month, when both Microsoft and Adobe publish the security updates to their products – the so-called Patch Tuesday.
But before we get into the details of their updates for the month (17 in all) let’s reiterate the urgency of another vulnerability that might have slipped by you. The popular open source program ImageMagick is currently under active attack on the Internet. Vulnerability CVE-2016-3714 (called ImageTragick in the ass
Qualys
Update: Patch Tuesday May 2016 | Qualys
blogs_qualys·2016-05-12·CVSS 7.5
CVE-2016-4117 [HIGH] Update: Patch Tuesday May 2016 | Qualys
Update : Adobe released the patch for Adobe Flash that addresses the current 0-day CVE-2016-4117 in APSB16-15 . It also patches another 24 vulnerabilities that are mostly rated critical. Patch as quickly as possible. Chrome and Internet Explorer 11/Edge users will get their patches from Google and Microsoft automatically.
Original : Today is the second Tuesday of the month, when both Microsoft and Adobe publish the security updates to their products – the so-called Patch Tuesday.
But before we get into the details of their updates for the month (17 in all) let’s reiterate the urgency of another vulnerability that might have slipped by you. The popular open source program ImageMagick is currently under active attack on the Internet. Vulnerability CVE-2016-3714 (called ImageTragick in the
Zscaler
Zscaler found Multiple Security Vulnerabilities | 06-16-2016
blogs_zscaler
Zscaler found Multiple Security Vulnerabilities | 06-16-2016
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Zscaler
Zscaler found Multiple Security Vulnerabilities | 05-13-2016
blogs_zscaler
Zscaler found Multiple Security Vulnerabilities | 05-13-2016
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Threat Intel
APT37 (APT37, InkySquid, ScarCruft)
threat_intel
APT37 (APT37, InkySquid, ScarCruft)
# Threat Actor Profile: APT37
ATT&CK ID: G0067
Also known as: APT37, InkySquid, ScarCruft, Reaper, Group123, TEMP.Reaper, Ricochet Chollima
Suspected origin: China
## Overview
APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.(Citation: FireEye APT37 Feb 2018)(Citation: Securelist ScarCruft Jun 2016)(Citation: Talos Group123)
North Korean group definitions are
arXiv
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
arxiv_fulltext·2025-02-12
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Almuthanna Alageel
and
Sergio Maffeis
Department of Computing
Imperial College London
London, United Kingdom
plain
plain
## Abstract
The scarcity of data and the high complexity of Advanced Persistent Threats (APTs) attacks have created challenges in comprehending their behavior and hindered the exploration of effective detection techniques.
To create an effective APT detection strategy, it is important to examine the Tactics, Techniques, and Procedures (TTPs) that have been reported by the industry. These TTPs can be difficult to classify as either malicious or legitimate. When developing an approach for the next generation of network intrusion detection systems (NIDS), it is necessary to
arXiv
On the Effectiveness of Type-based Control Flow Integrity
arxiv_fulltext·2020-02-14
On the Effectiveness of Type-based Control Flow Integrity
2018
2018
acmcopyright
[ACSAC '18]2018 Annual Computer Security Applications ConferenceDecember 3--7, 2018San Juan, PR, USA
2018 Annual Computer Security Applications Conference (ACSAC '18), December 3--7, 2018, San Juan, PR, USA
15.00
10.1145/3274694.3274739
978-1-4503-6569-7/18/12
On the Effectiveness of Type-based Control Flow Integrity
Reza Mirzazade farkhani
Northeastern University
[email protected]
Saman Jafari
Northeastern University
[email protected]
Sajjad Arshad
Northeastern University
[email protected]
William Robertson
Northeastern University
[email protected]
Engin Kirda
Northeastern University
[email protected]
Hamed Okhravi
MIT Lincoln Laboratory
[email protected]
## Abstract
Control flow integrity (CFI) has received significant attention in the community
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-15
bugzilla·2016-05-11·CVSS 7.5
CVE-2016-4117 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-15
flash-plugin: multiple code execution issues fixed in APSB16-15
Adobe released a new security advisory for Adobe Flash Player.
A critical vulnerability (CVE-2016-4117) exists in Adobe Flash Player 21.0.0.226 and earlier versions for Windows, Macintosh, Linux, and Chrome OS. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.
Adobe is aware of a report that an exploit for CVE-2016-4117 exists in the wild. Adobe will address this vulnerability in our monthly security update, which will be available as early as May 12. For the latest information, users may monitor the Adobe Product Security Incident Response Team blog.
https://helpx.adobe.com/security/products/flash-player/apsa16-02.html
Discussion:
Updates for Adobe Flas
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00047.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1079.htmlhttp://www.securityfocus.com/bid/90505http://www.securitytracker.com/id/1035826https://helpx.adobe.com/security/products/flash-player/apsa16-02.htmlhttps://helpx.adobe.com/security/products/flash-player/apsb16-15.htmlhttps://security.gentoo.org/glsa/201606-08https://www.exploit-db.com/exploits/46339/http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00047.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1079.htmlhttp://www.securityfocus.com/bid/90505http://www.securitytracker.com/id/1035826https://helpx.adobe.com/security/products/flash-player/apsa16-02.htmlhttps://helpx.adobe.com/security/products/flash-player/apsb16-15.htmlhttps://security.gentoo.org/glsa/201606-08https://www.exploit-db.com/exploits/46339/https://github.com/cisagov/vulnrichment/issues/196https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-4117
2016-05-11
Published
2022-03-03
Added to CISA KEV
Exploited in the wild