CVE-2016-4271 is a local-with-filesystem Flash sandbox bypass vulnerability in Adobe Flash Player versions before 18.0.0.375 and 23.0.0.162 on Windows/OS X, and before 11.2.202.635 on Linux, allowing attackers to bypass access restrictions and obtain sensitive information. With a CVSS score of 6.5 (Medium), this vulnerability requires user interaction and could lead to high confidentiality impact. While there is no known public exploit code or Metasploit module, the vulnerability has garnered some community discussion and media coverage, including reports of its potential to leak Windows credentials. It is not listed in CISA's KEV catalog and is considered inactive.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.2.202.632CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 22.0.0.211CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 22.0.0.211CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 22.0.0.211CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 18.0.0.366CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.