CVE-2016-7855 is a critical use-after-free vulnerability in Adobe Flash Player, affecting Windows, OS X, and Linux versions. This flaw allows remote attackers to execute arbitrary code through unspecified vectors. With a CVSS score of 8.8 (High), it presents a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. This vulnerability was actively exploited in the wild in October 2016, as confirmed by its presence in the CISA KEV catalog and extensive media coverage, including reports linking it to Russian-backed cyber espionage. While no public exploit code is listed for Metasploit, Nuclei, or ExploitDB, its active exploitation and high community discussion indicate a well-understood and leveraged threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 23.0.0.185CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 23.0.0.185CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 23.0.0.185CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 11.2.202.637CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:linux:*:* | ||
<= 23.0.0.185CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.