cbcvebase.
CVE-2016-4171
published 2016-06-16

CVE-2016-4171: Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in…

PriorityP185critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
19.90%
97.1th percentile
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.

Affected

13 ranges
VendorProductVersion rangeFixed in
adobeflash_player<= 11.2.202.621
adobeflash_player<= 21.0.0.242
adobeflash_player<= 18.0.0.352
opensuseopensuse
opensuseopensuse
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
suselinux_enterprise_desktop
suselinux_enterprise_workstation_extension

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2016-4171 affects Adobe Flash Player 21.0.0.242 and earlier; any Flash Player at or below this version should be treated as vulnerable and targeted for detection/blocking
  • Kaspersky Lab's exploit prevention technology detected CVE-2016-4171 in the wild; endpoint products with exploit prevention/PDM components should be used to detect this Flash zero-day
  • CVE-2016-4171 was attributed to DarkHotel (Operation Daybreak); threat hunting should look for DarkHotel TTPs including spear-phishing lures and Flash exploit delivery via compromised/hacked websites
  • ·Adobe acknowledged active exploitation of CVE-2016-4171 before a patch was available and delayed the expected monthly Flash patch; the advisory referenced is APSA16-03
  • ·EMET was noted as providing protection against CVE-2016-4171 exploitation prior to patching

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.