CVE-2016-7892: Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.
Other sources
Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disconnect or isolate any systems running Macromedia/Adobe Flash Player (notably versions 23.0.0.207 and earlier, 11.2.202.644 and earlier) from networks and untrusted access if still in use; restrict access to management/trusted IPs only until the product is removed or replaced.
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7892?
CVE-2016-7892 has a high severity rating as it allows for arbitrary code execution.
How do I fix CVE-2016-7892?
To mitigate CVE-2016-7892, update Adobe Flash Player to version 24.0.0.194 or later.
Which versions of Adobe Flash Player are affected by CVE-2016-7892?
CVE-2016-7892 affects Adobe Flash Player versions 23.0.0.207 and earlier, and 11.2.202.644 and earlier.
What types of systems are vulnerable to CVE-2016-7892?
CVE-2016-7892 impacts Adobe Flash Player running on various systems including Windows and macOS.
Is there a workaround for CVE-2016-7892 until I can update?
There are no specific workarounds for CVE-2016-7892; users are strongly advised to apply the necessary updates.