CVE-2016-4171: Adobe Flash Player Remote Code Execution Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 20.1% chance of exploitation in the next 30 days.
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
Affected products
- Adobe Flash Player: up to and including 11.2.202.621; up to and including 21.0.0.242; up to and including 18.0.0.352
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only
- Suse Linux Enterprise Desktop: version 12 only
- Suse Linux Enterprise Workstation Extension: version 12 only
Published 2016-06-16. Last modified 2026-06-17.