CVE-2016-4273 is a critical memory corruption vulnerability affecting Adobe Flash Player versions before 18.0.0.382 and 23.0.0.185 on Windows and OS X, and before 11.2.202.637 on Linux, potentially leading to arbitrary code execution or denial of service. With a CVSS score of 8.8 (High), it presents a significant risk due to its network-based attack vector and low attack complexity, allowing unauthenticated attackers to achieve high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, a public exploit (EDB-40510) exists, and the vulnerability garnered notable community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 23.0.0.162CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 23.0.0.162CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 23.0.0.162CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 18.0.0.375CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:* | ||
<= 23.0.0.162CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.