First published: Wed Sep 14 2016(Updated: )
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4275, CVE-2016-4276, CVE-2016-4280, CVE-2016-4281, CVE-2016-4282, CVE-2016-4283, CVE-2016-4284, CVE-2016-4285, CVE-2016-6922, and CVE-2016-6924.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | <=11.2.202.632 | |
Linux Kernel | ||
Windows 10 | ||
Microsoft Windows | ||
Macromedia Flash Player | <=22.0.0.211 | |
Macromedia Flash Player | <=22.0.0.211 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
Adobe Flash Player | <=22.0.0.211 | |
Macromedia Flash Player | <=18.0.0.366 | |
Macromedia Flash Player | <=22.0.0.211 | |
Chrome OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4274 has a critical severity rating due to its potential to allow remote code execution and cause a denial of service.
To fix CVE-2016-4274, update Adobe Flash Player to version 23.0.0.162 or later for affected platforms.
CVE-2016-4274 affects Adobe Flash Player versions before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and macOS, as well as specific versions on Linux.
Yes, CVE-2016-4274 can be exploited remotely, allowing attackers to execute arbitrary code on vulnerable systems.
Adobe Flash Player versions prior to 18.0.0.375 and 19.x through 22.0.0.211 are vulnerable and need to be updated.