← Vulnerability feed

Vulnerability record · CVE-2016-4171 · published 16 June 2016

CVE-2016-4171: Adobe Flash Player unspecified remote code execution flaw

Adobe · Flash Player

CVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code through unknown vectors. Adobe and CISA both confirm it was exploited in the wild in June 2016, and the record provides no root-cause detail beyond that. Because the flaw is remotely reachable with no privileges or user interaction per the CVSS vector, it is a serious risk anywhere Flash remains installed.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 EPSS 20% · top 2.6%
9.8CVSS 3.1 base score, v2 10.0
20%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
7Affected product versions listed by NVD
22References
17 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 9.8, confirmed in-the-wild exploitation, and CISA KEV listing make this a critical priority despite the thin technical description.

What it is

CVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code through unknown vectors. Adobe and CISA both confirm it was exploited in the wild in June 2016, and the record provides no root-cause detail beyond that. Because the flaw is remotely reachable with no privileges or user interaction per the CVSS vector, it is a serious risk anywhere Flash remains installed.

Impact

A successful attack lets a remote attacker run arbitrary code in the context of the Flash Player process, which typically means full compromise of the affected host or browser session. The record does not specify the exact code-execution primitive or any secondary impact such as data theft or persistence.

Attack surface

The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N, so the flaw is network-reachable, requires no authentication and no user interaction. The description says only 'unknown vectors', so the precise delivery path (for example a malicious SWF or web page) is not stated in the record.

Exploitation

CVE-2016-4171 is listed in CISA KEV (added 2022-03-25) and the description states it was exploited in the wild in June 2016. EPSS gives a 30-day probability of 0.20211 at the 97.3rd percentile, indicating elevated likelihood of exploitation activity.

What to do

  • Apply the Adobe Flash Player update referenced in Adobe advisory APSB16-18 (or the corresponding Red Hat, SUSE, openSUSE or Gentoo errata) to any system still running Flash.
  • Because Flash Player is end-of-life, remove or disable the plugin entirely and disconnect affected systems as CISA's KEV required action states.
  • Block Flash content at the browser and network layer, and restrict outbound access to untrusted sites that could deliver a malicious SWF.
  • Inventory hosts and browsers still carrying Flash Player 21.0.0.242 or earlier and prioritize them for remediation or decommissioning.

Detection

  • Hunt for Flash Player versions at or below 21.0.0.242 across endpoints and browsers using software inventory or file-version checks.
  • Monitor for unexpected child processes spawned by browser or Flash Player processes, which can indicate code execution from a malicious SWF.
  • Review proxy, IDS and DNS logs for requests to known malicious SWF or exploit-kit hosts around the June 2016 exploitation window and later.
  • Alert on Flash Player crashes or abnormal memory behavior on hosts that still have the plugin enabled.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-4171 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Adobe Flash Player Remote Code Execution Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 15 April 2022.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/91184 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036094 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2016:1238 Third Party Advisory
https://helpx.adobe.com/security/products/flash-player/apsa16-03.html Vendor Advisory
https://helpx.adobe.com/security/products/flash-player/apsb16-18.html Vendor Advisory
https://security.gentoo.org/glsa/201606-08 Third Party Advisory
https://www.kb.cert.org/vuls/id/748992 Third Party AdvisoryUS Government Resource
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00031.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00035.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00038.html Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/91184 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036094 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2016:1238 Third Party Advisory
https://helpx.adobe.com/security/products/flash-player/apsa16-03.html Vendor Advisory
https://helpx.adobe.com/security/products/flash-player/apsb16-18.html Vendor Advisory
https://security.gentoo.org/glsa/201606-08 Third Party Advisory
https://www.kb.cert.org/vuls/id/748992 Third Party AdvisoryUS Government Resource
https://github.com/cisagov/vulnrichment/issues/196 Issue Tracking
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-4171 US Government Resource

Track CVE-2016-4171 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-5544OpenSLP heap out-of-bounds write in VMware ESXi and Horizon DaaSOpenSLP as shipped in VMware ESXi and Horizon DaaS contains a heap overwrite (out-of-bounds write) flaw. VMware rates it Critical with a maximum CVSS…KEVEPSS 97%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2016-1019Adobe Flash Player memory corruption allows code executionAdobe Flash Player 21.0.0.197 and earlier contains an unspecified memory corruption flaw that can crash the application or allow arbitrary code execu…KEVEPSS 22%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed9.8CVE-2015-5122Adobe Flash Player ActionScript 3 Use-After-Free in DisplayObjectA use-after-free flaw in the DisplayObject class of Adobe Flash Player's ActionScript 3 implementation is triggered by crafted Flash content that mis…KEVEPSS 94%analysed

Source: NIST National Vulnerability Database (record CVE-2016-4171), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.