Vulnerability Intelligence Report
CVE-2016-4138
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:25.42%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| redhat | enterprise_linux_desktop | 5.0, 6.0 |
| redhat | enterprise_linux_server | 5.0, 6.0 |
| redhat | enterprise_linux_workstation | 5.0, 6.0 |
| adobe | flash_player | all |
| adobe | flash_player_desktop_runtime | all |
| apple | macos | all |
| chrome_os | all | |
| linux | linux_kernel | all |
| microsoft | windows | all |
| microsoft | windows_10 | 1511 |
| microsoft | windows_8.1 | all |
| opensuse | opensuse | 13.1, 13.2 |
| suse | linux_enterprise_desktop | 12 |
| suse | linux_enterprise_workstation_extension | 12 |
| microsoft | windows_rt_8.1 | all |
| microsoft | windows_server_2012 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
25.419%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Adobe Systems Incorporated · Vendor · USA |
| Reserved | 2016-04-27T00:00:00 |
| Published | 2016-06-16T14:00:00 |
| Patch Date | 2016-06-14 |
| Last Updated | 2024-08-06T00:17:31 |
Community Chatter & Buzz