First published: Thu Dec 15 2016(Updated: )
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the MovieClip class when handling conversion to an object. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player | <=23.0.0.207 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
Macromedia Flash Player | <=23.0.0.207 | |
Macromedia Flash Player | <=23.0.0.207 | |
Windows 10 | ||
Microsoft Windows | ||
Macromedia Flash Player | <=23.0.0.207 | |
Chrome OS | ||
Linux Kernel | ||
Macromedia Flash Player | <=11.2.202.644 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7881 is considered a critical vulnerability that could lead to arbitrary code execution in affected Adobe Flash Player versions.
To fix CVE-2016-7881, update Adobe Flash Player to version 23.0.0.208 or later.
CVE-2016-7881 affects Adobe Flash Player versions 23.0.0.207 and earlier, as well as 11.2.202.644 and earlier.
Successful exploitation of CVE-2016-7881 could allow attackers to execute arbitrary code on the affected system.
Yes, CVE-2016-7881 poses a remote code execution risk if successfully exploited.