#VU1078 Use-after-free error in Adobe Flash Player and Adobe Flash Player for Linux - CVE-2016-7855

 

#VU1078 Use-after-free error in Adobe Flash Player and Adobe Flash Player for Linux - CVE-2016-7855

Published: October 26, 2016 / Updated: March 8, 2022


Vulnerability identifier: #VU1078
Vulnerability risk: Critical
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Red
CVE-ID: CVE-2016-7855
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
Adobe Flash Player
Adobe Flash Player for Linux
Software vendor:
Adobe

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to use-after-free error when handling .swf files. A remote attacker can trick the victim to visit a website or open a file with malicious Flash file and execute arbitrary code on the target system with privileges of the current user.

Note: this vulnerability was being actively exploited in the wild.


Remediation

The vulnerability is fixed in version 23.0.0.205 for Windows, Macintosh, Linux and Chrome OS and in version 11.2.202.643 for Linux.

External links