Use-after-free error in Adobe Flash Player for Linux and Adobe Flash Player - CVE-2016-7855
Published: October 26, 2016 / Updated: March 8, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to use-after-free error when handling .swf files. A remote attacker can trick the victim to visit a website or open a file with malicious Flash file and execute arbitrary code on the target system with privileges of the current user.
Note: this vulnerability was being actively exploited in the wild.
Affected software
Adobe Flash Player
Arch Linux
Microsoft Windows
Windows Server
How to mitigate CVE-2016-7855
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Remote code execution in Adobe Flash Player
- Microsoft Security Update for Adobe Flash Player
- Security Update for Adobe Flash Player (3201860)
- Arch Linux update for lib32-flashplugin
- Arch Linux update for flashplugin
- OpenSUSE Linux update for flash-player
- OpenSUSE Linux update for flash-player
- SUSE Linux update for flash-player