CVE-2016-7873Out-of-bounds Write in Adobe Flash Player

Severity
8.8HIGHNVD
EPSS
5.1%
top 10.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15
Latest updateMay 14

Description

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable memory corruption vulnerability in the PSDK class related to ad policy functionality method. Successful exploitation could lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8g2g-mp63-vpxx: Adobe Flash Player versions 232022-05-14
CVEList
CVE-2016-7873: Adobe Flash Player versions 232016-12-15

📋Vendor Advisories

1
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-392016-12-13

🕵️Threat Intelligence

1
Unit42
Palo Alto Networks Unit 42 Vulnerability Research December 2016 Disclosures2016-12-16

💬Community

1
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-392016-12-13
CVE-2016-7873 — Out-of-bounds Write in Adobe | cvebase