Security bypass in Adobe products - CVE-2016-4286
Published: October 13, 2016 / Updated: March 6, 2017
Vulnerability identifier: #VU958
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4286
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The weakness exists due to access control error. A remote attacker can create a specially crafted Web site, trick the victim into opening it, to avoid security controls and obtain potentially sensitive information.
Successful exploitation of the vulnerability may result in information disclosure on the vulnerable system.
The weakness exists due to access control error. A remote attacker can create a specially crafted Web site, trick the victim into opening it, to avoid security controls and obtain potentially sensitive information.
Successful exploitation of the vulnerability may result in information disclosure on the vulnerable system.
Affected software
Adobe Flash Player for Linux
Adobe Flash Player Extended Support Release
Adobe Flash Player
Microsoft Windows
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Windows Server
Adobe Flash Player Extended Support Release
Adobe Flash Player
Microsoft Windows
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Windows Server
How to mitigate CVE-2016-4286
Update Adobe Flash Player Desktop Runtime for Google Chrome, Windows and Macintosh, Microsoft Edge and Internet Explorer 11 to version 23.0.0.185;
Update Adobe Flash Player Extended Support Release to version 18.0.0.382;
Update Adobe Flash Player for Linux to version 11.2.202.637.
Update Adobe Flash Player Extended Support Release to version 18.0.0.382;
Update Adobe Flash Player for Linux to version 11.2.202.637.