Vulnerability Intelligence Report
Adobe Flash Player Remote Code Execution Vulnerability
CVE-2016-4171
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:19.90%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| adobe | flash_player | all |
| linux | linux_kernel | all |
| apple | mac_os_x | all |
| apple | macos | all |
| microsoft | windows | all |
| chrome_os | all | |
| microsoft | windows_8.1 | all |
| microsoft | windows_10 | all |
| redhat | enterprise_linux_desktop | 5.0, 6.0 |
| redhat | enterprise_linux_server | 5.0, 6.0 |
| redhat | enterprise_linux_workstation | 5.0, 6.0 |
| opensuse | opensuse | 13.1, 13.2 |
| suse | linux_enterprise_desktop | 12 |
| suse | linux_enterprise_workstation_extension | 12 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Adobe Systems Incorporated · Vendor · USA |
| Reserved | 2016-04-27T00:00:00 |
| Published | 2016-06-16T14:00:00 |
| Patch Date | 2016-06-14 |
| Last Updated | 2025-11-17T19:40:40 |
Community Chatter & Buzz