Cyber Resilience

CVE-2016-4171

Adobe Flash Player ≤ 11.2.202.621

CISA KEVActive ExploitationEUVD Exploited
Published
16 June 2016
Modified
21 April 2026
KEV Added
25 March 2022
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.20 97th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2016-4171 is a critical-severity an unspecified weakness vulnerability in Adobe Flash Player. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 3% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2016-4171 is an unspecified vulnerability affecting Adobe Flash Player versions 21.0.0.242 and earlier. The flaw carries a CVSS score of 9.8 and is categorized under NVD-CWE-noinfo, indicating insufficient details were available at the time of disclosure to assign a more specific weakness identifier.

Remote attackers can exploit the issue over the network without authentication or user interaction to execute arbitrary code, resulting in complete compromise of confidentiality, integrity, and availability on affected systems. The vulnerability was observed being exploited in the wild during June 2016.

Security advisories referenced in OpenSUSE mailing lists, SecurityFocus, and SecurityTracker address the issue through updated packages and vendor patches for supported distributions and platforms. The public references primarily consist of distribution-specific announcements rather than detailed technical analysis from the vendor.

EU & UK References

Vulnerability Data

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.

CWE(s)
KEV Date Added
25 March 2022

Related Threats

CVEs Like This One

CVE-2014-0497Same product: Adobe Flash Playerboth on KEV
CVE-2012-1535Same product: Adobe Flash Playerboth on KEV
CVE-2018-4878Same product: Adobe Flash Playerboth on KEV
CVE-2012-2034Same product: Adobe Flash Playerboth on KEV
CVE-2015-7645Same product: Adobe Flash Playerboth on KEV
CVE-2017-11292Same product: Adobe Flash Playerboth on KEV
CVE-2018-15982Same product: Adobe Flash Playerboth on KEV
CVE-2018-5002Same product: Adobe Flash Playerboth on KEV
CVE-2014-0502Same product: Adobe Flash Playerboth on KEV
CVE-2013-0643Same product: Adobe Flash Playerboth on KEV

Affected Assets

adobe
flash player
≤ 11.2.202.621 · ≤ 21.0.0.242 · ≤ 21.0.0.242
redhat
enterprise linux desktop
5.0, 6.0
redhat
enterprise linux server
5.0, 6.0
redhat
enterprise linux workstation
5.0, 6.0
opensuse
opensuse
13.1, 13.2
suse
linux enterprise desktop
12
suse
linux enterprise workstation extension
12

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References