cbcvebase.
CVE-2016-7892
published 2016-12-15

CVE-2016-7892: Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class…

PriorityP180high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
18.79%
97.0th percentile
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

Affected

3 ranges
VendorProductVersion rangeFixed in
adobeflash_player<= 23.0.0.207
adobeflash_player<= 11.2.202.644
adobeflash_player_desktop_runtime<= 23.0.0.207

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2016-7892 was a 0-day vulnerability in Adobe Flash Player being actively exploited in targeted attacks in the wild at time of disclosure (December 2016)
  • The vulnerability resides in the TextField class of Adobe Flash Player; detection/hunting should focus on Flash content triggering TextField use-after-free conditions
  • Adobe Flash Player (flash-plugin package on Linux) is the affected component; presence of flash-plugin versions 23.0.0.207 or earlier / 11.2.202.644 or earlier indicates a vulnerable host
  • If Adobe Flash Player is still present/in-use, it should be treated as a high-priority finding; CISA designates this as a Known Exploited Vulnerability requiring disconnection of the end-of-life product
  • ·Vulnerability affects two distinct Flash Player version branches; both must be checked when assessing exposure
  • ·The flash-plugin package on Red Hat Enterprise Linux 5 is marked 'Will not fix', meaning patching via the OS vendor is not available for that platform

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.