CVE-2016-4153
HIGH severity · CVSS 8.8 · Out-of-bounds write
8.8CVSS HIGH
Summary
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges requiredNone
User interactionRequired
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)4%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Official patch: https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-083 ↗
Additional information
- NVD record
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-083Patch
- https://helpx.adobe.com/security/products/flash-player/apsb16-18.htmlPatch
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.htmlAdvisory
- http://www.securitytracker.com/id/1036117Advisory
- https://access.redhat.com/errata/RHSA-2016:1238Advisory