CVE-2016-4249: Buffer Overflow
Published Jul 13, 2016
·Updated
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors.
Affected Software
12 affected components
Adobe Flash Player Desktop Runtime<=22.0.0.192
Apple iOS and macOS
Microsoft Windows
Adobe Flash Player<=18.0.0.360
Adobe Flash Player Chrome<=22.0.0.192
Google Chrome OS
Linux Linux kernel
Adobe Flash Player Edge<=22.0.0.192
Adobe Flash Player Internet Explorer<=22.0.0.192
Microsoft Windows 10
Microsoft Windows 8.1
Adobe Flash Player<=11.2.202.626
Remediation
Event History
Jul 13, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4249?
CVE-2016-4249 has been rated as critical due to its potential for allowing arbitrary code execution.
2
How do I fix CVE-2016-4249?
To mitigate CVE-2016-4249, update Adobe Flash Player to the latest version beyond 22.0.0.209.
3
Which versions of Adobe Flash Player are affected by CVE-2016-4249?
CVE-2016-4249 affects Adobe Flash Player versions prior to 18.0.0.366 and from 19.x through 22.x before 22.0.0.209 on various platforms.
4
What platforms are impacted by CVE-2016-4249?
CVE-2016-4249 impacts Adobe Flash Player on Windows, OS X, and Linux systems.
5
Can CVE-2016-4249 be exploited remotely?
Yes, CVE-2016-4249 can be exploited remotely via untrusted vectors, which may lead to arbitrary code execution.