CVE-2016-6992 is a critical type confusion vulnerability in Adobe Flash Player, affecting versions before 18.0.0.382, 19.x through 23.x before 23.0.0.185 on Windows and OS X, and before 11.2.202.637 on Linux. This flaw allows remote attackers to execute arbitrary code with high impact on confidentiality, integrity, and availability, requiring user interaction to exploit. While no public exploit code (Metasploit, Nuclei, ExploitDB) is readily available, the vulnerability received significant community discussion and media coverage at the time, indicating its importance. It is not currently listed on CISA's KEV catalog, suggesting it is not under active widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 23.0.0.162CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 23.0.0.162CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 23.0.0.162CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 18.0.0.375CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:* | ||
<= 23.0.0.162CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.