CVE-2016-7855
published 2016-11-01CVE-2016-7855: Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute…
PriorityP181high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
25.20%
97.7th percentile
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 23.0.0.185 | — |
| adobe | flash_player | <= 11.2.202.637 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The exploit is delivered via malicious RTF documents containing embedded OLE Word documents, which in turn embed malicious SWF files; hunt for RTF files with embedded OLE objects that contain SWF content. ↗
- →DealersChoice Variant B loads the malicious SWF and payload entirely in memory without writing to disk; use memory-scanning or behavioral detection rather than relying solely on file-based AV. ↗
- →The Sofacy group uses geolocation filtering on C2 servers to only serve exploit payloads to targets in specific regions; sandbox detonation from non-targeted geographies may not trigger payload delivery. ↗
- →Weaponized documents use the OfficeTestSideloading technique to sideload DLLs via a Microsoft Office performance test module; monitor for unusual DLL loads from Office processes or the OfficeTest registry key. ↗
- →Two decoy documents (NASAMS.doc and Programm_Details.doc) share the unique 'Last Saved By' metadata value 'pain'; this metadata artifact can be used to cluster related Sofacy phishing documents. ↗
- ·The C2 server randomizes k1, k2, k3, k4 token/key values per request, so these cannot be used as static network signatures. ↗
- ·The C2 server applies geolocation filtering and will not serve payloads to requests originating from non-targeted regions (e.g., USA), limiting sandbox/automated analysis effectiveness. ↗
- ·The C2 server serves different exploit SWF files based on the victim's reported Flash Player version; the CVE-2016-7855 SWF (c993c1e1…) is only delivered when the Flash version is reported as 23.0.0.185 or similarly vulnerable. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Adobe Flash Player Use-After-Free Vulnerability
cisa·2022-03-03·CVSS 8.8
CVE-2016-7855 [HIGH] CWE-416 Adobe Flash Player Use-After-Free Vulnerability
Vulnerability: Adobe Flash Player Use-After-Free Vulnerability
Affected: Adobe Flash Player
Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code.
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-7855
Remediation Due Date: 2022-03-24
Red Hat
flash-plugin: use-after-free issue fixed in APSB16-36
vendor_redhat·2016-10-26·CVSS 8.8
CVE-2016-7855 [HIGH] flash-plugin: use-after-free issue fixed in APSB16-36
flash-plugin: use-after-free issue fixed in APSB16-36
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.
GHSA
GHSA-fq8g-m89m-mrw9: Use-after-free vulnerability in Adobe Flash Player before 23
ghsa_unreviewed·2022-05-14
CVE-2016-7855 [HIGH] CWE-416 GHSA-fq8g-m89m-mrw9: Use-after-free vulnerability in Adobe Flash Player before 23
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.
OSV
CVE-2016-7855: Use-after-free vulnerability in Adobe Flash Player before 23
osv·2016-11-01·CVSS 8.8
CVE-2016-7855 [HIGH] CVE-2016-7855: Use-after-free vulnerability in Adobe Flash Player before 23
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.
VulnCheck
Adobe Flash Player Use-After-Free Vulnerability
vulncheck·2016·CVSS 8.8
CVE-2016-7855 [HIGH] CWE-416 Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player Use-After-Free Vulnerability
Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code.
Affected: Adobe Flash Player
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cve.org/CVERecord?id=CVE-2016-7855; https://unit42.paloaltonetworks.com/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue/; https://us-cert.cisa.gov/sites/default/files/publications/AR-17-20045_Enhanced_Analysis_of_GRIZZLY_STEPPE_Activity.pdf; https://dl.acm.org/doi/pdf/10.1145/3465481.3465758; https://www.cisa.gov/sites/default/files/feeds/known_exploite
No detection rules found.
No public exploits indexed.
Unit42
Let It Ride: The Sofacy Group’s DealersChoice Attacks Continue
blogs_unit42·2016-12-15·CVSS 7.8
[HIGH] Let It Ride: The Sofacy Group’s DealersChoice Attacks Continue
Recently, Palo Alto Networks Unit 42 reported on a new exploitation platform that we called “DealersChoice” in use by the Sofacy group (AKA APT28, Fancy Bear, STRONTIUM, Pawn Storm, Sednit). As outlined in our original posting, the DealersChoice exploitation platform generates malicious RTF documents which in turn use embedded OLE Word documents. These embedded OLE Word documents then contain embedded Adobe Flash (.SWF) files that are designed to exploit Abode Flash vulnerabilities.
At the time of initial reporting, we found two variants:
1. Variant A: A standalone variant that included Flash exploit code packaged with a payload.
2. Variant B: A modular variant that loaded exploit code on-demand and appeared non-operational at the time.
Since that time, we have been able to collect addi
Unit42
Let It Ride: The Sofacy Group’s DealersChoice Attacks Continue
blogs_unit42·2016-12-15·CVSS 7.8
[HIGH] Let It Ride: The Sofacy Group’s DealersChoice Attacks Continue
Threat Research Center
Threat Research
Malware
## Let It Ride: The Sofacy Group’s DealersChoice Attacks Continue
Robert Falcone
Bryan Lee
Published: December 15, 2016
Malware
Threat Actor Groups
Threat Research
DealersChoice
Fighting Ursa
Sofacy
Threat research
Recently, Palo Alto Networks Unit 42 reported on a new exploitation platform that we called “DealersChoice” in use by the Sofacy group (AKA APT28, Fancy Bear, STRONTIUM, Pawn Storm, Sednit). As outlined in our original posting, the DealersChoice exploitation platform generates malicious RTF documents which in turn use embedded OLE Word documents. These embedded OLE Word documents then contain embedded Adobe Flash (.SWF) files that are designed to exploit Abode Flash vulnerabilities.
At the time of initial reporting,
Qualys
Emergency Flash Player 0-day update released by Adobe
blogs_qualys·2016-10-26·CVSS 8.8
CVE-2016-7855 [HIGH] Emergency Flash Player 0-day update released by Adobe
Adobe released APSB16-36 today to fix one 0-day vulnerability in Flash. The vulnerability is currently being used in active attacks and therefore Adobe released this emergency fix. If left un-patched, attackers can remotely take complete control of the machine. The vulnerability (CVE-2016-7855) is triggered when the victim views malicious Adobe flash content. Usually innocent users end up with malicious flash content by clicking on bad links from e-mails, blogs, bulletin boards and other sources.
All platforms including Windows, Macintosh, Linux and Chrome OS are affected. It’s a use-after-free issues in which the software attempts to access memory after it has been freed, which can cause a program to crash or in this case can result in the execution of attacker supplied code. The updated
Qualys
Emergency Flash Player 0-day update released by Adobe | Qualys
blogs_qualys·2016-10-26·CVSS 8.8
CVE-2016-7855 [HIGH] Emergency Flash Player 0-day update released by Adobe | Qualys
Adobe released APSB16-36 today to fix one 0-day vulnerability in Flash. The vulnerability is currently being used in active attacks and therefore Adobe released this emergency fix. If left un-patched, attackers can remotely take complete control of the machine. The vulnerability (CVE-2016-7855) is triggered when the victim views malicious Adobe flash content. Usually innocent users end up with malicious flash content by clicking on bad links from e-mails, blogs, bulletin boards and other sources.
All platforms including Windows, Macintosh, Linux and Chrome OS are affected. It’s a use-after-free issues in which the software attempts to access memory after it has been freed, which can cause a program to crash or in this case can result in the execution of attacker supplied code. The updated
Zscaler
Zscaler discovers Flash Player Vulnerabilities | 10-11-2016
blogs_zscaler
Zscaler discovers Flash Player Vulnerabilities | 10-11-2016
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
arXiv
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
arxiv_fulltext·2025-02-12
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Almuthanna Alageel
and
Sergio Maffeis
Department of Computing
Imperial College London
London, United Kingdom
plain
plain
## Abstract
The scarcity of data and the high complexity of Advanced Persistent Threats (APTs) attacks have created challenges in comprehending their behavior and hindered the exploration of effective detection techniques.
To create an effective APT detection strategy, it is important to examine the Tactics, Techniques, and Procedures (TTPs) that have been reported by the industry. These TTPs can be difficult to classify as either malicious or legitimate. When developing an approach for the next generation of network intrusion detection systems (NIDS), it is necessary to
Bugzilla
CVE-2016-7855 flash-plugin: use-after-free issue fixed in APSB16-36
bugzilla·2016-10-26·CVSS 8.8
CVE-2016-7855 [HIGH] CVE-2016-7855 flash-plugin: use-after-free issue fixed in APSB16-36
CVE-2016-7855 flash-plugin: use-after-free issue fixed in APSB16-36
Adobe Security Bulletin APSB16-36 for Adobe Flash Player describes a flaw that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB16-36:
These updates resolve a use-after-free vulnerability that could lead to code
execution (CVE-2016-7855).
External References:
https://helpx.adobe.com/security/products/flash-player/apsb16-36.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5 Supplementary
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:2119 https://rhn.redhat.com/errata/RHSA-2016-2119.html
http://rhn.redhat.com/errata/RHSA-2016-2119.htmlhttp://www.securityfocus.com/bid/93861http://www.securitytracker.com/id/1037111https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-128https://helpx.adobe.com/security/products/flash-player/apsb16-36.htmlhttps://security.gentoo.org/glsa/201610-10https://security.googleblog.com/2016/10/disclosing-vulnerabilities-to-protect.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2119.htmlhttp://www.securityfocus.com/bid/93861http://www.securitytracker.com/id/1037111https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-128https://helpx.adobe.com/security/products/flash-player/apsb16-36.htmlhttps://security.gentoo.org/glsa/201610-10https://security.googleblog.com/2016/10/disclosing-vulnerabilities-to-protect.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-7855
2016-11-01
Published
2022-03-03
Added to CISA KEV
Exploited in the wild