CVE-2016-7892: Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.
Other sources
Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disconnect Adobe Flash Player from the environment if it is still in use, because the impacted product is end-of-life.
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7892?
CVE-2016-7892 has a high severity rating as it allows for arbitrary code execution.
How do I fix CVE-2016-7892?
To mitigate CVE-2016-7892, update Adobe Flash Player to version 24.0.0.194 or later.
Which versions of Adobe Flash Player are affected by CVE-2016-7892?
CVE-2016-7892 affects Adobe Flash Player versions 23.0.0.207 and earlier, and 11.2.202.644 and earlier.
What types of systems are vulnerable to CVE-2016-7892?
CVE-2016-7892 impacts Adobe Flash Player running on various systems including Windows and macOS.
Is there a workaround for CVE-2016-7892 until I can update?
There are no specific workarounds for CVE-2016-7892; users are strongly advised to apply the necessary updates.