CVE-2016-7892
published 2016-12-15CVE-2016-7892: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class…
PriorityP180high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
18.79%
97.0th percentile
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 23.0.0.207 | — |
| adobe | flash_player | <= 11.2.202.644 | — |
| adobe | flash_player_desktop_runtime | <= 23.0.0.207 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2016-7892 was a 0-day vulnerability in Adobe Flash Player being actively exploited in targeted attacks in the wild at time of disclosure (December 2016) ↗
- →The vulnerability resides in the TextField class of Adobe Flash Player; detection/hunting should focus on Flash content triggering TextField use-after-free conditions ↗
- →Adobe Flash Player (flash-plugin package on Linux) is the affected component; presence of flash-plugin versions 23.0.0.207 or earlier / 11.2.202.644 or earlier indicates a vulnerable host ↗
- →If Adobe Flash Player is still present/in-use, it should be treated as a high-priority finding; CISA designates this as a Known Exploited Vulnerability requiring disconnection of the end-of-life product ↗
- ·Vulnerability affects two distinct Flash Player version branches; both must be checked when assessing exposure ↗
- ·The flash-plugin package on Red Hat Enterprise Linux 5 is marked 'Will not fix', meaning patching via the OS vendor is not available for that platform ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Adobe Flash Player Use-After-Free Vulnerability
cisa·2022-03-25·CVSS 8.8
CVE-2016-7892 [HIGH] CWE-416 Adobe Flash Player Use-After-Free Vulnerability
Vulnerability: Adobe Flash Player Use-After-Free Vulnerability
Affected: Adobe Flash Player
Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-7892
Remediation Due Date: 2022-04-15
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-39
vendor_redhat·2016-12-13·CVSS 8.8
CVE-2016-7892 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-39
flash-plugin: multiple code execution issues fixed in APSB16-39
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.
Package: flash-plugin (Red Hat Enterprise Linux 5) - Will not fix
GHSA
GHSA-gxjf-m829-568r: Adobe Flash Player versions 23
ghsa_unreviewed·2022-05-14
CVE-2016-7892 [CRITICAL] CWE-416 GHSA-gxjf-m829-568r: Adobe Flash Player versions 23
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.
VulnCheck
Adobe Flash Player Use-After-Free Vulnerability
vulncheck·2016·CVSS 8.8
CVE-2016-7892 [HIGH] CWE-416 Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.
Affected: Adobe Flash Player
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-04-15
No detection rules found.
No public exploits indexed.
Qualys
2016 Year-End Summary for Adobe and Another 0-day Fix in December
blogs_qualys·2016-12-14·CVSS 8.8
CVE-2016-7892 [HIGH] 2016 Year-End Summary for Adobe and Another 0-day Fix in December
Adobe released nine security bulletins today in the December Security updates. The most notable update was APSB16-39 for Flash which fixed a 0-day vulnerability with exploits in the wild that is being used in targeted attacks. Adobe products including Flash and Acrobat PDF reader have long being targeted by exploit kits. In addition to the 0-day (CVE-2016-7892), 17 other vulnerabilities were fixed in Flash. This update address critical vulnerabilities that could potentially allow an attacker to take control of the affected system. Other updates included in today’s release fixed Coldfusion ( APSB16-44 ) , Robohelp ( APSB16-46 ), Adobe Digital Editions ( APSB16-45 ), InDesign ( APSB16-43 ) , Experience Manager ( APSB16-42 ) , DNG Converter ( APSB16-41 ) and Animate ( APSB16-38 ).
In 2016 Ad
Qualys
2016 Year-End Summary for Adobe and Another 0-day Fix in December | Qualys
blogs_qualys·2016-12-14·CVSS 8.8
CVE-2016-7892 [HIGH] 2016 Year-End Summary for Adobe and Another 0-day Fix in December | Qualys
Adobe released nine security bulletins today in the December Security updates. The most notable update was APSB16-39 for Flash which fixed a 0-day vulnerability with exploits in the wild that is being used in targeted attacks. Adobe products including Flash and Acrobat PDF reader have long being targeted by exploit kits. In addition to the 0-day (CVE-2016-7892), 17 other vulnerabilities were fixed in Flash. This update address critical vulnerabilities that could potentially allow an attacker to take control of the affected system. Other updates included in today’s release fixed Coldfusion (APSB16-44) , Robohelp (APSB16-46), Adobe Digital Editions (APSB16-45), InDesign (APSB16-43) , Experience Manager (APSB16-42) , DNG Converter (APSB16-41) and Animate (APSB16-38).
In 2016 Adobe vulnerabil
Zscaler
Zscaler discovers Flash Player Vulnerabilities | 12-13-2016
blogs_zscaler
Zscaler discovers Flash Player Vulnerabilities | 12-13-2016
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-39
bugzilla·2016-12-13·CVSS 8.8
CVE-2016-7872 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-39
flash-plugin: multiple code execution issues fixed in APSB16-39
Adobe Security Bulletin APSB16-39 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB16-39:
These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2016-7872, CVE-2016-7877, CVE-2016-7878, CVE-2016-7879, CVE-2016-7880, CVE-2016-7881, CVE-2016-7892).
These updates resolve buffer overflow vulnerabilities that could lead to code execution (CVE-2016-7867, CVE-2016-7868, CVE-2016-7869, CVE-2016-7870).
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2016-7871, CVE-2016-7873, CVE-2016-7874, CVE-2016-7875, CVE-2016-7876).
Thes
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00064.htmlhttp://lists.opensuse.org/opensuse-updates/2016-12/msg00112.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2947.htmlhttp://www.securityfocus.com/bid/94877http://www.securitytracker.com/id/1037442https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-154https://helpx.adobe.com/security/products/flash-player/apsb16-39.htmlhttps://security.gentoo.org/glsa/201701-17http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00064.htmlhttp://lists.opensuse.org/opensuse-updates/2016-12/msg00112.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2947.htmlhttp://www.securityfocus.com/bid/94877http://www.securitytracker.com/id/1037442https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-154https://helpx.adobe.com/security/products/flash-player/apsb16-39.htmlhttps://security.gentoo.org/glsa/201701-17https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-7892
2016-12-15
Published
2022-03-25
Added to CISA KEV
Exploited in the wild