CVE-2016-7855: Adobe Flash Player Use-After-Free Vulnerability
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.
Other sources
Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Flash Player (Windows and OS X)to a version that resolves this vulnerability.Fixed in 23.0.0.205 - Upgrade
Upgrade
Adobe Flash Player (Linux)to a version that resolves this vulnerability.Fixed in 11.2.202.643 - Compensating control
Disconnect the impacted product (Adobe Flash Player) if it is still in use, as the product is end-of-life.
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7855?
CVE-2016-7855 is classified as a critical vulnerability due to its ability to allow remote code execution.
How do I fix CVE-2016-7855?
To fix CVE-2016-7855, update Adobe Flash Player to version 23.0.0.205 or later.
What versions of Adobe Flash Player are affected by CVE-2016-7855?
CVE-2016-7855 affects Adobe Flash Player versions before 23.0.0.205 on Windows and macOS and versions before 11.2.202.643 on Linux.
Can CVE-2016-7855 be exploited remotely?
Yes, CVE-2016-7855 can be exploited remotely, allowing attackers to execute arbitrary code.
What kind of vulnerability is CVE-2016-7855?
CVE-2016-7855 is a use-after-free vulnerability, which occurs when memory that is no longer needed is accessed.