← Back to CVE List
Vulnerability Intelligence Report
Adobe Flash Player Use-After-Free Vulnerability

CVE-2016-7892

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:18.79%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-416 ↗CWE-416 Use After Free

Affected Products & Versions

Vendor Product Affected Versions
adobe flash_player_desktop_runtime all
apple mac_os_x all
microsoft windows all
adobe flash_player all
microsoft windows_10 all
microsoft windows_8.1 all
google chrome_os all
linux linux_kernel all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
18.786%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityAdobe Systems Incorporated · Vendor · USA
Reserved2016-09-09T00:00:00
Published2016-12-15T06:31:00
Patch Date2016-12-14
Last Updated2025-10-21T23:55:47

LINK COPIED TO CLIPBOARD