Vulnerability Description
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Flash Player | <= 21.0.0.226 |
| Redhat | Enterprise Linux Desktop | 5.0 |
| Redhat | Enterprise Linux Server | 5.0 |
| Redhat | Enterprise Linux Server From Rhui | 5.0 |
| Redhat | Enterprise Linux Workstation | 5.0 |
| Opensuse | Evergreen | 11.4 |
| Opensuse | Opensuse | 13.1 |
| Suse | Linux Enterprise Desktop | 12 |
| Suse | Linux Enterprise Workstation Extension | 12 |
References
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00046.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00047.htmlMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1079.htmlThird Party Advisory
- http://www.securityfocus.com/bid/90505Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1035826Broken LinkThird Party AdvisoryVDB Entry
- https://helpx.adobe.com/security/products/flash-player/apsa16-02.htmlBroken LinkVendor Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb16-15.htmlBroken Link
- https://security.gentoo.org/glsa/201606-08Third Party Advisory
- https://www.exploit-db.com/exploits/46339/ExploitThird Party AdvisoryVDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00046.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00047.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2016-4117?
CVE-2016-4117 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
How severe is CVE-2016-4117?
CVE-2016-4117 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-4117?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Flash Player, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Server From Rhui, Redhat Enterprise Linux Workstation.