Skip to main content

CVE detail

CVE-2016-4117

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

CVSS 9.8 · CriticalBuzz score 71.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 71.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
56 evidence mentions in the snapshot
Diversity score
16.0
6 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
56 source links · newest first
  • The APT28 group is trying to exploit the CVE-2017-11292 Flash zero-day before users receive patches or update their systems. Security experts at Proofpoint collected evidence of several malware campaigns, powered by the Russian APT28 group, that rely on a Flash zero-day vulnerability that Adobe patched earlier this week. According to the experts who observed attacks on organizations […]

    newssecurityaffairs.comOct 22, 2017, 11:29 AM
  • Security researchers from Kaspersky Labs spotted the BlackOasis APT group exploiting a new zero-day RCE vulnerability in Adobe Flash. Security researchers from Kaspersky Labs have discovered a new zero-day remote code execution vulnerability in Adobe Flash, tracked as CVE-2017-11292, which was being actively exploited by hackers in the wild to deliver the surveillance software FinSpy. Hackers belonging to the […]

    newssecurityaffairs.comOct 17, 2017, 7:05 AM
  • A threat group believed to be located somewhere in the Middle East has been using a zero-day vulnerability in Adobe Flash Player to deliver a piece of spyware to targeted individuals.

    newswww.securityweek.comOct 16, 2017, 3:38 PM
  • A new exploit kit (EK) has emerged recently on underground forums, where a malware developer is advertising it starting at just $80.

    newswww.securityweek.comAug 15, 2017, 12:46 PM
  • The Disdain exploit kit is available for rent on a daily, weekly, or monthly basis for prices of $80, $500, and $1,400 respectively. The security researcher David Montenegro discovered a new exploit kit dubbed Disdain that is offered for rent on underground hacking forums by a malware developer using the pseudonym of Cehceny. https://twitter.com/CryptoInsane/status/895151680861253632 The Disdain exploit […]

    newssecurityaffairs.comAug 15, 2017, 7:48 AM
  • The Stegano exploit kit, also known as Astrum, continues to evolve, recently its authors adopted the Diffie-Hellman algorithm to hinder analysis. The Stegano exploit kit made was associated in the past with a massive AdGholas malvertising campaign that delivered malware, mostly Gozi and RAMNIT trojans. Experts at TrendMicro also observed the exploit kit in the Seamless malvertising campaign. “Astrum’s […]

    newssecurityaffairs.comMay 20, 2017, 7:31 PM
  • After receiving multiple updates, the Stegano exploit kit (EK) recently adopted the Diffie-Hellman algorithm to hinder analysis, Trend Micro security researchers warn.

    newswww.securityweek.comMay 19, 2017, 11:59 AM
  • Exploit kits: Winter 2017 reviewMalwarebytes Labs

    A few months have passed since our Fall 2016 review of the most common exploit kits we are seeing in our telemetry and honeypots. Today, we take another look at the current (bleak) EK scene by going over RIG, Sundown, Neutrino and Magnitude. There haven’t been any major changes in the past little while and exploit kit-related infections remain low compared to those via malicious spam. This is in part due to the lack of fresh and reliable exploits in today’s drive-by landscape. Pseudo-Darkleech and EITest are the most popular redirection campaigns from compromised websites. They refer to code that is injected into – for the most part – WordPress , Joomla , or Drupal websites and automatically redirects visitors to an exploit kit landing page. Malvertising campaigns keep fuelling redirections to exploit kits as well, but can greatly vary in size and impact. The daily malverts from shady ad networks continue unchanged while the larger attacks going after top ad networks and publishers co…

    newswww.malwarebytes.comMar 8, 2017, 5:00 PM
  • It’s a new year and while some things change, some things stay the same (or similar). There’s lots of FUD about the sophisticated cyber attacks that are multi-threaded and obfuscated. Certainly there are attacks that fall into this category, but if you look at all of the cybercrime activity from the past year, it’s clear that the majority of threats do not have the level of sophistication that is often talked about.

    newswww.securityweek.comJan 20, 2017, 4:16 PM
  • Based on an analysis in 2015 of over 100 exploit kits (EKs) and known vulnerabilities, Adobe Flash was the unfortunate winner of the most frequently exploited product. Now that it’s 2017, companies are joking that maybe it’s time to give Flash the old heave ho’ to retirement. While Adobe has worked tirelessly to make Flash more […]

    newswww.csoonline.comJan 17, 2017, 7:00 PM
  • Experts from Heimdal Security warned of a spike in cyber attacks leveraging the popular RIG Exploit kit to deliver the Cerber Ransomware. The RIG exploit kit is even more popular in the criminal ecosystem, a few days ago security experts at Heimdal Security warned of a spike in cyber attacks leveraging the popular Neutrino and […]

    newssecurityaffairs.comJan 16, 2017, 6:44 AM
  • A newly observed campaign leveraging the RIG exploit kit is targeting outdated versions of popular applications such as Flash, Internet Explorer, or Microsoft Edge to distribute the Cerber ransomware, Heimdal Security warns.

    newswww.securityweek.comJan 15, 2017, 6:55 PM
  • New Terror Exploit Kit EmergesSecurityWeek

    After the fall of the Nuclear and Angler exploit kits (EKs), overall activity generated from exploit kits has dropped to only a fraction of what used to be.

    newswww.securityweek.comJan 10, 2017, 4:59 PM
  • A new variant of the Sundown exploit kit leverages on steganography to hide exploit code in harmless-looking image files. Security experts from Trend Micro have spotted a new version of the Sundown exploit kit that exploits steganography in order to hide malicious code in harmless-looking image files. The use of steganography was recently observed in the malvertising campaigns conducted […]

    newssecurityaffairs.comDec 30, 2016, 7:46 PM
  • A new version of the Sundown exploit kit uses a technique called steganography to hide its exploits in harmless-looking image files, Trend Micro reported on Thursday.

    newswww.securityweek.comDec 30, 2016, 10:31 AM
  • Microsoft discovered two distinct APT groups, PROMETHIUM and NEODYMIUM, that exploited the same Flash Player zero-day flaw on same targets. Security researchers have discovered two distinct APT groups, PROMETHIUM and NEODYMIUM, that exploited the same Flash Player zero-day vulnerability (CVE-2016-4117) in cyber espionage campaigns on Turkish citizens living in Turkey and various other European countries. Both […]

    newssecurityaffairs.comDec 16, 2016, 10:59 AM
  • Researchers at Microsoft have observed two separate advanced persistent threat (APT) actors that leveraged the same Flash Player zero-day vulnerability to spy on Turkish citizens living in Turkey and various other European countries.

    newswww.securityweek.comDec 15, 2016, 11:03 AM
  • Experts from the firm Recorded Future published a report on the most common vulnerabilities used by threat actors in the exploit kits. Recorded Future published an interesting report on the most common vulnerabilities used by threat actors in the exploit kits. The experts observed that Adobe Flash Player and Microsoft products (Internet Explorer, Silverlight, Windows) continue […]

    newssecurityaffairs.comDec 6, 2016, 8:18 PM
  • The most common vulnerabilities used by exploit kits in the past year affect Flash Player, Windows, Internet Explorer and Silverlight, according to a report published on Tuesday by threat intelligence firm Recorded Future.

    newswww.securityweek.comDec 6, 2016, 3:28 PM
  • Exploit kits: Fall 2016 reviewMalwarebytes Labs

    There have been interesting developments with exploit kits in the past few months to say the least, with the disappearance of…

    newswww.malwarebytes.comNov 8, 2016, 5:00 PM
  • Unit 42 has reported on various Sofacy group attacks over the last year, most recently with a post on Komplex, an OS X variant of a tool commonly used by the Sofacy group. In the same timeframe of the Komplex attacks, we collected several weaponized documents that use a tactic previously not observed in use

    vendorunit42.paloaltonetworks.comOct 17, 2016, 8:00 PM
  • Sundown, a relatively new exploit kit (EK), is outsourcing panel and Domain Generation Algorithm (DGA) coding work and stealing exploits in an attempt to improve its presence on the EK scene.

    newswww.securityweek.comSep 5, 2016, 1:46 PM
  • A look into some RIG exploit kit campaignsMalwarebytes Labs

    In the past few weeks we’ve talked about the Neutrino and Magnitude exploit kits. This time, we take a look at…

    newswww.malwarebytes.comJul 25, 2016, 5:00 PM
  • Operators behind the Neutrino EK have added the code to exploit an Internet Explorer flaw that was recently patched with the release of the MS16-053. Operators behind the infamous Neutrino EK have recently added the code to exploit an Internet Explorer vulnerability that was patched with the release of the MS16-053 security bulletin. The MS16-053 bulletin patched […]

    newssecurityaffairs.comJul 15, 2016, 1:20 PM
  • The developers of the Neutrino exploit kit have added a recently patched Internet Explorer vulnerability to their arsenal after researchers published a proof-of-concept (PoC) exploit.

    newswww.securityweek.comJul 15, 2016, 7:44 AM
  • Neutrino EK: fingerprinting in a FlashMalwarebytes Labs

    Since the disappearance of Angler EK, exploit kit activity is at one of its lowest it has been in a long…

    newswww.malwarebytes.comJun 27, 2016, 5:00 PM
  • Adobe Flash Player 22.0.0.192 release fixes the Flash Player zero-day vulnerability (CVE-2016-4171) exploited by the APT group dubbed ScarCruft. Adobe has issued the Flash Player 22.0.0.192, a release that fixes the Flash Player zero-day vulnerability (CVE-2016-4171) exploited by the APT group dubbed ScarCruft in attacks on high-profile targets. The Flash Player flaw CVE-2016-4171 affects versions 21.0.0.242 and earlier for […]

    newssecurityaffairs.comJun 19, 2016, 1:29 PM
  • Adobe has patched the Flash Player zero-day vulnerability exploited by a relatively new advanced persistent threat (APT) group dubbed “ScarCruft” in attacks aimed at high-profile targets.

    newswww.securityweek.comJun 17, 2016, 8:08 AM
  • Adobe has issued a patch for the Plash Player zero-day vulnerability (CVE-2016-4171) that is actively exploited by the ScarCruft APT group. The bug, discovered by Anton Ivanov of Kaspersky Labs, is being used in “limited, targeted attacks.” According to Kaspersky, the group has been spotted using zero-day exploits before, and is currently engaged in two major operations. “The first of them, Operation Daybreak, appears to have been launched by ScarCruft in March 2016 and employs … More →

    newswww.helpnetsecurity.comJun 17, 2016, 12:59 AM
  • A zero-day vulnerability affecting the latest version of Adobe Flash Player and all previous ones is being actively exploited in limited, targeted attacks, the company has announced on Tuesday. The flaw (CVE-2016-4171) exists in Adobe Flash Player and 21.0.0.242 and earlier versions for Windows, Macintosh, Linux, and Chrome OS, and can be exploited to cause a crash and potentially allow an attacker to take control of the affected system. Kaspersky Lab’s Costin Raiu offered some … More →

    newswww.helpnetsecurity.comJun 15, 2016, 2:20 PM
  • Security experts from Kaspersky Lab revealed that an APT group dubbed ScarCruft exploited the zero day vulnerability (CVE-2016-4171) in Adobe Flash Player. According to the experts from Kaspersky Lab, an APT group dubbed ScarCruft exploited a zero day vulnerability (CVE-2016-4171) in Adobe Flash Player. The group launched a series of attacks against high-profile targets against entities in […]

    newssecurityaffairs.comJun 15, 2016, 2:15 PM
  • The Flash Player zero-day vulnerability whose existence was brought to light on Tuesday by Adobe has been exploited by a relatively new advanced persistent threat (APT) group named by Kaspersky Lab “ScarCruft.”

    newswww.securityweek.comJun 15, 2016, 7:28 AM
  • Adobe has released security updates for several of its products, but a critical Flash Player zero-day vulnerability exploited in targeted attacks will only be resolved later this week.

    newswww.securityweek.comJun 14, 2016, 4:36 PM
  • Update (06/13/2016): Still no sign of Angler EK activity since late June 6th PST. In the meantime, the actor known as ihateclowns/SadClowns…

    newswww.malwarebytes.comJun 10, 2016, 5:00 PM
  • Security experts from the SANS observed that new CryptXXX ransomware campaigns are leveraging on the Neutrino Exploit Kit instead the Angler Exploit Kit. Crooks behind the CryptXXX ransomware have launched a new campaign leveraging on the Neutrino Exploit Kit instead the Angler Exploit Kit. It was a significant change in the attack chain that was discovered by the experts […]

    newssecurityaffairs.comJun 10, 2016, 6:03 AM
  • Malware authors are using various techniques to evade detection, and those operating the Cerber ransomware are now employing a server-side “malware factory” , researchers at Invincea reveal.

    newswww.securityweek.comJun 3, 2016, 10:37 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Let me inform you that I’m one of the finalists for the best European Security Blog, please vote for SecurityAffairs in all the sessions it is mentioned. https://www.surveymonkey.com/r/secbloggerwards2016 #securityaffairs Security Affairs newsletter Round 61 – News of […]

    newssecurityaffairs.comMay 29, 2016, 10:47 AM
  • A recently patched Adobe Flash Player vulnerability is being abused in a new malvertising campaign that redirects users to the Angler exploit kit (EK), Malwarebytes researchers warn.

    newswww.securityweek.comMay 26, 2016, 2:00 PM
  • A well known malvertising gang famous for its use of the fingerprinting technique and other evasion tricks to bypass security checks has been ramping…

    newswww.malwarebytes.comMay 24, 2016, 5:00 PM
  • It took hackers less than two weeks to integrate a recently patched Flash Player exploit into widely used Web-based attack tools that are being used to infect computers with malware. The vulnerability, known as CVE-2016-4117, was discovered earlier this month by security researchers FireEye. It was exploited in targeted attacks through malicious Flash content embedded […]

    newswww.csoonline.comMay 23, 2016, 3:19 PM
  • Here’s an overview of some of last week’s most interesting news and articles: The life of a social engineer: Hacking the human A clean-cut guy with rimmed glasses and a warm smile, Jayson E. Street looks nothing like the stereotypical hacker regularly portrayed in movies (i.e. pale, grim and antisocial). But he is one – he just “hacks” humans. LinkedIn users’ data on sale on the dark web A hacker has put up a batch … More →

    newswww.helpnetsecurity.comMay 23, 2016, 11:00 AM
  • The authors of the Magnitude exploit kit are integrating the exploit code for the CVE-2016-411 Adobe Flash Player vulnerability. Recently security experts from FireEye detailed the exploit chain for the Adobe Flaw Vulnerability CVE-2016-4117 that was first spotted by the company earlier May. The CVE-2016-4117 flaw affects older versions of the Adobe Flash, after the disclosure of […]

    newssecurityaffairs.comMay 23, 2016, 10:22 AM
  • The authors of the Magnitude exploit kit have already started integrating an exploit for a recently patched Adobe Flash Player vulnerability.

    newswww.securityweek.comMay 23, 2016, 9:24 AM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Let me inform you that I’m one of the finalists for the best European Security Blog, please vote for SecurityAffairs in all the sessions it is mentioned. https://www.surveymonkey.com/r/secbloggerwards2016 #securityaffairs Malware used in the recent banking cyberheists is […]

    newssecurityaffairs.comMay 22, 2016, 8:51 AM
  • Four days have passed since Adobe patched the latest Flash Player 0day vulnerability exploited in attacks in the wild and, in the meantime, we have been given more details about the attacks and the exploit used. Genwei Jiang, the FireEye researcher who has been credited, along with several others, with the discovery of the flaw (CVE-2016-4117), says that the initial attacks were leveraged against targets running Windows and Microsoft Office. “Attackers had embedded the Flash … More →

    newswww.helpnetsecurity.comMay 16, 2016, 10:06 PM
  • The popular crime forum Nulled.io has suffered a serious security breach that exposed personal details of more than 500K users and their activities. Nulled.io is a popular crime forum with roughly 500,000 users that but and sell any kind of product and services and share information regarding illegal practices. According to the Risk Based Security, last […]

    newssecurityaffairs.comMay 16, 2016, 8:36 PM
  • FireEye has shared some technical details on the Flash Player zero-day that was patched last week by Adobe and revealed that attackers have been exploiting the vulnerability via specially crafted Microsoft Office documents.

    newswww.securityweek.comMay 16, 2016, 6:22 PM
  • The FireEye researcher Genwei Jiang revealed the exploit chain related to phishing attacks leveraging CVE-2016-4117 flaw recently fixed by Adobe. Security experts at FireEye have recently spotted an attack leveraging on an Adobe zero-day vulnerability (CVE-2016-4117) recently patched. The CVE-2016-4117 flaw affects older versions of the Adobe Flash, a few days ago the company was informed of a new zero-day […]

    newssecurityaffairs.comMay 16, 2016, 1:27 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs How terrorists abuse online services for propaganda? Hacker Interviews – The hacker: zurael sTz Liberty Reserve founder sentenced 20 years in jail Security Affairs newsletter Round 59 – News of the week 2015 intelligence transparency report, the […]

    newssecurityaffairs.comMay 15, 2016, 11:32 AM
  • Adobe patches Flash 0day exploited in attacksHelp Net Security

    The Adobe Flash Player update announced earlier this week is here, and it fixes more than just the zero-day flaw exploited in attacks in the wild. All in all, the latest update plugs 25 security holes, all of which could lead to remote code execution, i.e. be leveraged to ultimately take over the system running a vulnerable version of Flash Player. No details have been shared about any of the fixed vulnerabilities, so as not … More →

    newswww.helpnetsecurity.comMay 13, 2016, 7:12 PM
  • Adobe Systems has released a security update for Flash Player in order to fix a publicly known vulnerability, as well as 24 privately reported security flaws. The company issued a warning about the zero-day — previously unknown and unpatched — vulnerability on Tuesday, saying that it is aware of an exploit available in the wild. […]

    newswww.csoonline.comMay 13, 2016, 2:38 PM
  • Adobe has updated Flash Player for Windows, Mac and Linux to address a total of 25 vulnerabilities, including a zero-day that has been exploited in the wild. Flash Player 21.0.0.242 and 11.2.202.616 patch type confusion, use-aftre-free, buffer overflow, directory search path, and various memory corruption vulnerabilities that can lead to arbitrary code execution.

    newswww.securityweek.comMay 12, 2016, 4:26 PM
  • On Tuesday, Adobe has pushed out security updates for Cold Fusion and Adobe Acrobat and Reader, but has also announced an update for Flash Player that should be released on Thursday and will fix a zero-day flaw (CVE-2016-4117) that’s being actively exploited in attacks in the wild. What kind of attacks? Adobe didn’t say. But the vulnerability is considered to be critical, as successful exploitation could cause a crash and potentially allow an attacker to … More →

    newswww.helpnetsecurity.comMay 11, 2016, 2:59 PM
  • Adobe Systems is working on a patch for a critical vulnerability in Flash Player that hackers are already exploiting in attacks. In the meantime, the company has released other security patches for Reader, Acrobat, and ColdFusion. The Flash Player vulnerability is being tracked as CVE-2016-4117 and affects Flash Player versions 21.0.0.226 and earlier for Windows, […]

    newswww.csoonline.comMay 11, 2016, 2:51 PM
  • CVE-2016-4117 is a zero-day vulnerability affecting the Adobe Flash Player that is being exploited to launch malware-based attacks in the wild. According to Adobe, a new zero-day vulnerability in the Flash Player software is being exploited in cyber attacks in the wild, and the worrisome new is that it will not be patched until May 12th. […]

    newssecurityaffairs.comMay 11, 2016, 5:48 AM
  • Adobe Flash Zero-Day Under AttackSecurityWeek

    A zero-day vulnerability in Adobe’s ubiquitous Flash Player software is being exploited to launch malware attacks, the company warned in an advisory issued today. The vulnerability, rated critical, will not be patched until May 12th.

    newswww.securityweek.comMay 10, 2016, 6:43 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence