Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Flash_player | — | Upgrade to Adobe Flash version 23.0.0.207 for Mac OS XUpgrade to Adobe Flash version 11.2.202.644 for LinuxUpgrade to Adobe Flash version 23.0.0.207 for Windows | Nov 8, 2016 | Nov 8, 2016 |
| Freebsd | — | Upgrade linux-c7-flashpluginUpgrade linux-c6-flashpluginUpgrade linux-f10-flashplugin | Nov 14, 2016 | Nov 10, 2016 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Nov 8, 2016 |
| Redhat_linux | — | Upgrade flash-plugin | Nov 9, 2016 | Nov 8, 2016 |
| Suse | — | Upgrade flash-player-gnomeUpgrade flash-player | Nov 10, 2016 | Nov 8, 2016 |
| Ubuntu | — | Upgrade flashplugin-nonfreeUpgrade adobe-flashplugin | Nov 19, 2024 | Nov 8, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub