CVE-2016-4171
published 2016-06-16CVE-2016-4171: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in…
PriorityP185critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
19.90%
97.1th percentile
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 11.2.202.621 | — |
| adobe | flash_player | <= 21.0.0.242 | — |
| adobe | flash_player | <= 18.0.0.352 | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_workstation_extension | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2016-4171 affects Adobe Flash Player 21.0.0.242 and earlier; any Flash Player at or below this version should be treated as vulnerable and targeted for detection/blocking ↗
- →Kaspersky Lab's exploit prevention technology detected CVE-2016-4171 in the wild; endpoint products with exploit prevention/PDM components should be used to detect this Flash zero-day ↗
- →CVE-2016-4171 was attributed to DarkHotel (Operation Daybreak); threat hunting should look for DarkHotel TTPs including spear-phishing lures and Flash exploit delivery via compromised/hacked websites ↗
- ·Adobe acknowledged active exploitation of CVE-2016-4171 before a patch was available and delayed the expected monthly Flash patch; the advisory referenced is APSA16-03 ↗
- ·EMET was noted as providing protection against CVE-2016-4171 exploitation prior to patching ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Flash Player up to 21.0.0.242 memory corruption (RHSA-2016:1238 / VU#748992)
vuldb·2026-04-23·CVSS 9.8
CVE-2016-4171 [CRITICAL] Adobe Flash Player up to 21.0.0.242 memory corruption (RHSA-2016:1238 / VU#748992)
A vulnerability was found in Adobe Flash Player up to 21.0.0.242. It has been rated as critical. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability is referenced as CVE-2016-4171. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
Upgrading the affected component is advised.
GHSA
GHSA-mgfm-9xxf-m8pm: Unspecified vulnerability in Adobe Flash Player 21
ghsa_unreviewed·2022-05-13
CVE-2016-4171 [CRITICAL] GHSA-mgfm-9xxf-m8pm: Unspecified vulnerability in Adobe Flash Player 21
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
OSV
CVE-2016-4171: Unspecified vulnerability in Adobe Flash Player 21
osv·2016-06-16·CVSS 9.8
CVE-2016-4171 [CRITICAL] CVE-2016-4171: Unspecified vulnerability in Adobe Flash Player 21
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
VulnCheck
Adobe Flash Player Remote Code Execution Vulnerability
vulncheck·2016·CVSS 9.8
CVE-2016-4171 [CRITICAL] Adobe Flash Player Remote Code Execution Vulnerability
Adobe Flash Player Remote Code Execution Vulnerability
Unspecified vulnerability in Adobe Flash Player allows for remote code execution.
Affected: Adobe Flash Player
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cve.org/CVERecord?id=CVE-2016-4171; https://securelist.com/operation-daybreak/75100/; https://dl.acm.org/doi/pdf/10.1145/3465481.3465758; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-04-15
VulnCheck
Microsoft XMP Core Services Improper Input Validation
vulncheck·2016·CVSS 8.8
CVE-2016-0147 [HIGH] Microsoft XMP Core Services Improper Input Validation
Microsoft XMP Core Services Improper Input Validation
Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulnerability."
Affected: Microsoft XMP Core Services
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://securelist.com/cve-2016-4171-adobe-flash-zero-day-used-in-targeted-attacks/75082/; https://securelist.com/operation-daybreak/75100/
VulnCheck
Adobe Flash Player Arbitrary Code Execution Vulnerability
vulncheck·2016·CVSS 9.8
CVE-2016-4117 [CRITICAL] Adobe Flash Player Arbitrary Code Execution Vulnerability
Adobe Flash Player Arbitrary Code Execution Vulnerability
An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.
Affected: Adobe Flash Player
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Known Ransomware Campaign Use: Known
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cve.org/CVERecord?id=CVE-2016-4117; https://security.berkeley.edu/news/vulnerable-adobe-flash-player-allows-remote-code-execution-cve-2016-4117; https://securelist.com/cve-2016-4171-adobe-flash-zero-day-used-in-targeted-attacks/75082/; https://securelist.com/operation-daybreak/75100/; https://ww
CISA
Adobe Flash Player Remote Code Execution Vulnerability
cisa·2022-03-25·CVSS 9.8
CVE-2016-4171 [CRITICAL] Adobe Flash Player Remote Code Execution Vulnerability
Vulnerability: Adobe Flash Player Remote Code Execution Vulnerability
Affected: Adobe Flash Player
Unspecified vulnerability in Adobe Flash Player allows for remote code execution.
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-4171
Remediation Due Date: 2022-04-15
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-18
vendor_redhat·2016-06-14·CVSS 9.8
CVE-2016-4171 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB16-18
flash-plugin: multiple code execution issues fixed in APSB16-18
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
No detection rules found.
No public exploits indexed.
Tenable
Cybersecurity Snapshot: 6 Things That Matter Right Now
blogs_tenable·2022-08-19
Cybersecurity Snapshot: 6 Things That Matter Right Now
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Analyzing the Vulnerabilities Associated with the Top Malware Strains of 2021
blogs_tenable·2022-08-04
Analyzing the Vulnerabilities Associated with the Top Malware Strains of 2021
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
APT Trends Report Q2 2018
blogs_securelist·2018-07-10
APT Trends Report Q2 2018
Authors
- GReAT
In the second quarter of 2017, Kaspersky Lab’s Global Research and Analysis Team (GReAT) began publishing summaries of the quarter’s private threat intelligence reports, in an effort to make the public aware of the research we have been conducting. This report serves as the latest installment, focusing on the relevant activities that we observed during Q2 2018.
These summaries are a representative snapshot of what has been discussed in greater detail in our private reports. They aim to highlight the significant events and findings that we feel people should be aware of. For brevity’s sake, we are choosing not to publish indicators associated with the reports highlighted. However, readers who would like to learn more about our intelligence reports or request more informat
Securelist
APT Trends Report Q2 2018
blogs_securelist·2018-07-10
APT Trends Report Q2 2018
Authors
GReAT
In the second quarter of 2017, Kaspersky Lab’s Global Research and Analysis Team (GReAT) began publishing summaries of the quarter’s private threat intelligence reports, in an effort to make the public aware of the research we have been conducting. This report serves as the latest installment, focusing on the relevant activities that we observed during Q2 2018.
These summaries are a representative snapshot of what has been discussed in greater detail in our private reports. They aim to highlight the significant events and findings that we feel people should be aware of. For brevity’s sake, we are choosing not to publish indicators associated with the reports highlighted. However, readers who would like to learn more about our intelligence reports or request more informatio
Securelist
Kaspersky Security Bulletin 2016. Review of the year. Overall statistics for 2016
blogs_securelist·2016-12-14
Kaspersky Security Bulletin 2016. Review of the year. Overall statistics for 2016
Table of Contents
- Introduction
- Six things we learned this year that we didn’t know before
- Other top threats
- The impact on business
Authors
- Kaspersky
## Executive Summary
Download Review of the year
Download Overall statistics
Download the consolidated Kaspersky Security Bulletin 2016
1. Kaspersky Security Bulletin. Predictions for 2017
2. Kaspersky Security Bulletin 2016. The ransomware revolution
## Introduction
If they were asked to sum up 2016 in a single word, many people around the world – particularly those in Europe and the US – might choose the word ‘unpredictable’. On the face of it, the same could apply to cyberthreats in 2016: the massive botnets of connected devices that paralysed much of the Internet in October; the relentless hacking of high profile websit
Securelist
Kaspersky Security Bulletin 2016. Review of the year. Overall statistics for 2016
blogs_securelist·2016-12-14
Kaspersky Security Bulletin 2016. Review of the year. Overall statistics for 2016
Table of Contents
Introduction
Six things we learned this year that we didn’t know before
1. That the underground economy is more sophisticated and bigger than ever: xDedic – the shady marketplace
2. That the biggest financial heist did not involve a stock exchange: the SWIFT-enabled transfers
3. That critical infrastructure is worryingly vulnerable: the BlackEnergy attacks
4. That a targeted attack can have no pattern: the ProjectSauron APT
5. That the online release of vast volumes of data can be an influential tactic: ShadowBrokers and other data dumps
6. That a camera could be part of a global cyber-army: the insecure Internet of Things
Other top threats
Inventive APTs
New zero-days
The hunt for financial gain
The ultimate vulnerability: people
Mobile advertising
The imp
Securelist
Windows zero-day exploit used in targeted attacks by FruityArmor APT
blogs_securelist·2016-10-20·CVSS 7.8
CVE-2016-3393 [HIGH] Windows zero-day exploit used in targeted attacks by FruityArmor APT
Table of Contents
Attack chain description
EOP zero-day details
Authors
Anton Ivanov
A few days ago, Microsoft published the “critical” MS16-120 security bulletin with fixes for vulnerabilities in Microsoft Windows, Microsoft Office, Skype for Business, Silverlight and Microsoft Lync.
One of the vulnerabilities – CVE-2016-3393 – was reported to Microsoft by Kaspersky Lab in September 2016.
Here’s a bit of background on how this zero-day was discovered. A few of months ago, we deployed a new set of technologies in our products to identify and block zero-day attacks. These technologies proved their effectiveness earlier this year, when we discovered two Adobe Flash zero-day exploits – CVE-2016-1010 and CVE-2016-4171. Two Windows EoP exploits have also been found with the help of this
Securelist
Windows zero-day exploit used in targeted attacks by FruityArmor APT
blogs_securelist·2016-10-20·CVSS 7.8
CVE-2016-3393 [HIGH] Windows zero-day exploit used in targeted attacks by FruityArmor APT
Table of Contents
- Attack chain description
- EOP zero-day details
Authors
- Anton Ivanov
A few days ago, Microsoft published the “critical” MS16-120 security bulletin with fixes for vulnerabilities in Microsoft Windows, Microsoft Office, Skype for Business, Silverlight and Microsoft Lync.
One of the vulnerabilities – CVE-2016-3393 – was reported to Microsoft by Kaspersky Lab in September 2016.
Here’s a bit of background on how this zero-day was discovered. A few of months ago, we deployed a new set of technologies in our products to identify and block zero-day attacks. These technologies proved their effectiveness earlier this year, when we discovered two Adobe Flash zero-day exploits – CVE-2016-1010 and CVE-2016-4171. Two Windows EoP exploits have also been found with the help of
Securelist
IT threat evolution in Q2 2016. Statistics
blogs_securelist·2016-08-11
IT threat evolution in Q2 2016. Statistics
Table of Contents
- Q2 figures
- Mobile threats
- Vulnerable applications exploited by cybercriminals
- Online threats (Web-based attacks)
Authors
- Roman Unuchek
- Maria Garnaeva
- Anton Ivanov
- Denis Makrushin
- Fedor Sinitsyn
Download the full report (PDF)
All the statistics used in this report were obtained using Kaspersky Security Network (KSN), a distributed antivirus network that works with various anti-malware protection components. The data was collected from KSN users who agreed to provide it. Millions of Kaspersky Lab product users from 213 countries and territories worldwide participate in this global exchange of information about malicious activity.
## Q2 figures
- According to KSN data, Kaspersky Lab solutions detected and repelled 171,895,830 malicious attacks from o
Qualys
Patch Tuesday June 2016 | Qualys
blogs_qualys·2016-06-14·CVSS 7.3
CVE-2016-4171 [HIGH] Patch Tuesday June 2016 | Qualys
It is Patch Tuesday June 2016, and Microsoft is coming out with 16 bulletins bringing fixing over 40 distinct vulnerabilities (CVEs). It brings up the half-year total to 81 which projects to a total of over 160 bulletins for 2016, a new record in terms of patches for the last decade.
But your primary attention should be on Adobe Flash. Adobe has acknowledged that a vulnerability (CVE-2016-4171) in the current Flash player is being used in the wild and delayed the expected monthly Adobe Flash patch. In their advisory APSA16-03 they promise the patch for the end of this week. Pay close attention to the release and address as quickly as possible. If you have EMET on your systems you are protected. By the way, this is the third month in a row that we are seeing a 0-day in Flash, making it mos
Qualys
Patch Tuesday June 2016 | Qualys
blogs_qualys·2016-06-14·CVSS 7.3
CVE-2016-4171 [HIGH] Patch Tuesday June 2016 | Qualys
It is Patch Tuesday June 2016, and Microsoft is coming out with 16 bulletins bringing fixing over 40 distinct vulnerabilities (CVEs). It brings up the half-year total to 81 which projects to a total of over 160 bulletins for 2016, a new record in terms of patches for the last decade.
But your primary attention should be on Adobe Flash. Adobe has acknowledged that a vulnerability (CVE-2016-4171) in the current Flash player is being used in the wild and delayed the expected monthly Adobe Flash patch. In their advisory APSA16-03 they promise the patch for the end of this week. Pay close attention to the release and address as quickly as possible. If you have EMET on your systems you are protected. By the way, this is the third month in a row that we are seeing a 0-day in Flash, making it mos
Zscaler
Zscaler found Multiple Security Vulnerabilities | 06-16-2016
blogs_zscaler
Zscaler found Multiple Security Vulnerabilities | 06-16-2016
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Recorded Future
Kickstart Threat Actor Research with Threat Actor Cards
blogs_recorded_future
Kickstart Threat Actor Research with Threat Actor Cards
# An Immediate Starting Point for Research on Threat Actor Groups
### Key Takeaways
- Recorded Future launches a new Intelligence Card™ for threat actor groups.
- Get content-rich, real-time alerts on new threat actor group activity.
- No more deciphering threat actor group aliases; get consolidated views of associated TTPs and IOCs.
Researching and analyzing threat actor groups requires a significant effort in both time and resource. Identifying if they’re criminal, hacktivist, or nation state groups and gathering intelligence on their chosen target organizations, asset types, and preferred methods could be fruitless without an understandable overview of the available data.
Threat actor group types and their preferred targets.
That’s why we’re pleased to announce a new feature in Rec
Recorded Future
Kickstart Threat Actor Research with Threat Actor Cards | Recorded Future
blogs_recorded_future
Kickstart Threat Actor Research with Threat Actor Cards | Recorded Future
## An Immediate Starting Point for Research on Threat Actor Groups
## Key Takeaways
Recorded Future launches a new Intelligence Card™ for threat actor groups.
Get content-rich, real-time alerts on new threat actor group activity.
No more deciphering threat actor group aliases; get consolidated views of associated TTPs and IOCs.
Researching and analyzing threat actor groups requires a significant effort in both time and resource. Identifying if they’re criminal, hacktivist, or nation state groups and gathering intelligence on their chosen target organizations, asset types, and preferred methods could be fruitless without an understandable overview of the available data.
Threat actor group types and their preferred targets.
That’s why we’re pleased to announce a new feature in Recorde
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-18
bugzilla·2016-06-15·CVSS 8.8
CVE-2016-4171 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-18
flash-plugin: multiple code execution issues fixed in APSB16-18
Adobe released a new security advisory for Adobe Flash Player.
A critical vulnerability (CVE-2016-4171) exists in Adobe Flash Player 21.0.0.242 and earlier versions for Windows, Macintosh, Linux, and Chrome OS. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.
Adobe is aware of a report that an exploit for CVE-2016-4171 exists in the wild, and is being used in limited, targeted attacks. Adobe will address this vulnerability in our monthly security update, which will be available as early as June 16. For the latest information, users may monitor the Adobe Product Security Incident Response Team blog.
https://helpx.adobe.com/security/products/flash-player/ap
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.htmlhttp://www.securityfocus.com/bid/91184http://www.securitytracker.com/id/1036094https://access.redhat.com/errata/RHSA-2016:1238https://helpx.adobe.com/security/products/flash-player/apsa16-03.htmlhttps://helpx.adobe.com/security/products/flash-player/apsb16-18.htmlhttps://security.gentoo.org/glsa/201606-08https://www.kb.cert.org/vuls/id/748992http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.htmlhttp://www.securityfocus.com/bid/91184http://www.securitytracker.com/id/1036094https://access.redhat.com/errata/RHSA-2016:1238https://helpx.adobe.com/security/products/flash-player/apsa16-03.htmlhttps://helpx.adobe.com/security/products/flash-player/apsb16-18.htmlhttps://security.gentoo.org/glsa/201606-08https://www.kb.cert.org/vuls/id/748992https://github.com/cisagov/vulnrichment/issues/196https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-4171
2016-06-16
Published
2022-03-25
Added to CISA KEV
Exploited in the wild