CVE-2016-4233 is a memory corruption vulnerability in Adobe Flash Player affecting versions before 18.0.0.366, 19.x through 22.x before 22.0.0.209 on Windows and OS X, and before 11.2.202.632 on Linux, impacting products from Adobe, Apple, Google, Linux, and Microsoft. This vulnerability allows attackers to execute arbitrary code or cause a denial of service. Rated with a CVSS score of 8.8 (High), this vulnerability has a network attack vector and low attack complexity, requiring user interaction. Successful exploitation could lead to high impacts on confidentiality, integrity, and availability. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While there is limited community discussion and media coverage, Adobe did release updates addressing this and many other vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 22.0.0.192CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 18.0.0.360CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:* | ||
<= 22.0.0.192CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 22.0.0.192CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 22.0.0.192CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.