#VU958 Security bypass in Adobe products - CVE-2016-4286
Published: October 13, 2016 / Updated: March 6, 2017
Vulnerability identifier: #VU958
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2016-4286
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Adobe Flash Player Extended Support Release
Adobe Flash Player for Linux
Adobe Flash Player
Adobe Flash Player Extended Support Release
Adobe Flash Player for Linux
Adobe Flash Player
Software vendor:
Adobe
Adobe
Description
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The weakness exists due to access control error. A remote attacker can create a specially crafted Web site, trick the victim into opening it, to avoid security controls and obtain potentially sensitive information.
Successful exploitation of the vulnerability may result in information disclosure on the vulnerable system.
The weakness exists due to access control error. A remote attacker can create a specially crafted Web site, trick the victim into opening it, to avoid security controls and obtain potentially sensitive information.
Successful exploitation of the vulnerability may result in information disclosure on the vulnerable system.
Remediation
Update Adobe Flash Player Desktop Runtime for Google Chrome, Windows and Macintosh, Microsoft Edge and Internet Explorer 11 to version 23.0.0.185;
Update Adobe Flash Player Extended Support Release to version 18.0.0.382;
Update Adobe Flash Player for Linux to version 11.2.202.637.
Update Adobe Flash Player Extended Support Release to version 18.0.0.382;
Update Adobe Flash Player for Linux to version 11.2.202.637.