CVE-2016-6923 is a use-after-free vulnerability in Adobe Flash Player affecting versions before 18.0.0.375, 19.x through 23.x before 23.0.0.162 on Windows and OS X, and before 11.2.202.635 on Linux. This flaw allows attackers to execute arbitrary code through unspecified vectors, impacting products from Adobe, Apple, Google, and Microsoft. With a CVSS v3.1 score of 8.8 (High), this vulnerability is remotely exploitable with low attack complexity, requiring user interaction, and can lead to high impacts on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has received some community and media attention, with Adobe releasing updates to address it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.2.202.632CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 22.0.0.211CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 22.0.0.211CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 22.0.0.211CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 18.0.0.366CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.