cbcvebase.
CVE-2016-7866
published 2016-12-15

CVE-2016-7866: Adobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code…

PriorityP264critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
15.78%
96.5th percentile
Adobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

Affected

1 ranges
VendorProductVersion rangeFixed in
adobeanimate<= 15.2.1.95

Detection & IOCsextracted from sources · hover to see the quote

filename.FLA
filename.JSFL
  • Detect malicious .FLA files with abnormally long ActionScript class names in the Class publish properties, which trigger a buffer overflow on open/save.
  • Monitor for .JSFL files bundled alongside .FLA files that invoke fl.getDocumentDOM().save() and fl.getDocumentDOM().testMovie(), a delivery vector for triggering the vulnerability.
  • Alert on Adobe Animate (Animate.exe) access violations or crashes when opening .FLA files or saving .as ActionScript files, indicative of memory corruption exploitation.
  • Flag .FLA files containing a MovieClip library item with an excessively long class name that extends MovieClip and is exported for ActionScript.
  • ·Exploitation is local/client-side; the attacker must socially engineer the victim into opening a crafted .FLA file and executing accompanying JSFL code.
  • ·Affected versions are Adobe Animate 15.2.1.95 and earlier; the vulnerability is triggered specifically by overly long class names in FLA Class publish properties.
  • ·The JSFL-based distribution method abuses the Flash JavaScript API (JSAPI), meaning standard file-type blocking of .FLA alone may be insufficient if JSFL execution is permitted.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.