CVE-2016-7881 is a critical use-after-free vulnerability in Adobe Flash Player versions 23.0.0.207 and earlier, and 11.2.202.644 and earlier, specifically within the MovieClip class during object conversion, affecting products from Adobe, Apple, Google, Linux, and Microsoft. This vulnerability carries a high CVSS score of 8.8, indicating a network-based attack with low complexity that requires user interaction, potentially leading to arbitrary code execution with high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV: No) and no public exploit intelligence (Metasploit, Nuclei, ExploitDB), it has garnered moderate community discussion and media coverage, suggesting awareness despite the lack of readily available exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 23.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 23.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 23.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 23.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 11.2.202.644CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.