CVE-2016-4171 is an unspecified critical vulnerability in Adobe Flash Player 21.0.0.242 and earlier, impacting a wide range of operating systems and vendors including Adobe, Apple, Google, Linux, Microsoft, OpenSUSE, Red Hat, and SUSE. With a CVSS score of 9.8, it allows remote attackers to execute arbitrary code with high impact on confidentiality, integrity, and availability, requiring no user interaction or complex attack conditions. This vulnerability was actively exploited in the wild by APT groups in June 2016, as confirmed by its presence in the KEV catalog and extensive media coverage. While no public exploit code is listed on Metasploit, Nuclei, or ExploitDB, its high EPSS score and significant community discussion underscore its historical importance and real-world exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.2.202.621CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 21.0.0.242CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 21.0.0.242CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 21.0.0.242CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 18.0.0.352CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.