CVE-2016-6921 is a use-after-free vulnerability in Adobe Flash Player, affecting versions before 18.0.0.375, 19.x through 23.x before 23.0.0.162 on Windows and OS X, and before 11.2.202.635 on Linux, impacting products from Adobe, Apple, Google, Linux, and Microsoft. With a CVSS v3.1 score of 8.8 (High), this vulnerability allows unauthenticated attackers to execute arbitrary code remotely with low attack complexity, leading to high confidentiality, integrity, and availability impacts. While no active exploitation is confirmed and no public exploit code exists in Metasploit, Nuclei, or ExploitDB, it has received some community and media attention, including an article from BleepingComputer.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.2.202.632CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 22.0.0.211CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 22.0.0.211CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 22.0.0.211CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 18.0.0.366CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.