CVE-2016-4244 is a critical memory corruption vulnerability affecting Adobe Flash Player versions before 18.0.0.366, 19.x through 22.x before 22.0.0.209 on Windows and OS X, and before 11.2.202.632 on Linux. This flaw, categorized as CWE-787, could allow an unauthenticated attacker to execute arbitrary code or cause a denial of service. With a CVSS v3.1 score of 8.8 (High), it requires user interaction (UI:R) but has low attack complexity (AC:L) and no privileges required (PR:N), making it a significant risk for confidentiality, integrity, and availability. While not listed on the KEV catalog or having public exploit code in Metasploit, Nuclei, or ExploitDB, it has received limited community discussion and media coverage, including a BleepingComputer article noting Adobe's update release.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 22.0.0.192CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 18.0.0.360CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:* | ||
<= 22.0.0.192CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 22.0.0.192CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 22.0.0.192CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.