First published: Wed Jul 13 2016(Updated: )
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4172, CVE-2016-4175, CVE-2016-4179, CVE-2016-4180, CVE-2016-4181, CVE-2016-4182, CVE-2016-4183, CVE-2016-4184, CVE-2016-4185, CVE-2016-4186, CVE-2016-4187, CVE-2016-4188, CVE-2016-4189, CVE-2016-4190, CVE-2016-4217, CVE-2016-4219, CVE-2016-4220, CVE-2016-4221, CVE-2016-4233, CVE-2016-4234, CVE-2016-4235, CVE-2016-4236, CVE-2016-4237, CVE-2016-4238, CVE-2016-4239, CVE-2016-4240, CVE-2016-4241, CVE-2016-4242, CVE-2016-4243, CVE-2016-4244, CVE-2016-4245, and CVE-2016-4246.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player | <=22.0.0.192 | |
Apple iOS and macOS | ||
Microsoft Windows | ||
Macromedia Flash Player | <=18.0.0.360 | |
Macromedia Flash Player | <=22.0.0.192 | |
Chrome OS | ||
Linux Kernel | ||
Macromedia Flash Player | <=22.0.0.192 | |
Macromedia Flash Player | <=22.0.0.192 | |
Microsoft Windows 10 | ||
Microsoft Windows 8.1 | ||
Macromedia Flash Player | <=11.2.202.626 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4218 currently has a high severity rating due to its potential to enable arbitrary code execution or result in denial of service.
To fix CVE-2016-4218, update Adobe Flash Player to version 22.0.0.209 or later for affected platforms.
CVE-2016-4218 affects Adobe Flash Player versions before 18.0.0.366 and versions 19.x through 22.x before 22.0.0.209.
The potential impacts of CVE-2016-4218 include execution of arbitrary code and memory corruption leading to denial of service.
Yes, systems like macOS, Windows 10, Windows 8.1, and Google Chrome OS are not vulnerable to CVE-2016-4218.