CVE Database · CVE-2016-7892
CVSS v3.1
8.8
EPSS
18.79%
Published
Dec 15, 2016
Modified
Apr 21, 2026
CISA Known Exploited Vulnerability
Added: 2022-03-25 · Due: 2022-04-15
The impacted product is end-of-life and should be disconnected if still in use.
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HWeaknesses (CWE)
Affected Products (14)
References (17)