CVE detail
CVE-2016-4171
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 9.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
12 source links · newest first
Adobe today released security updates for Flash Player, Acrobat, Reader, and XMP Toolkit for Java, to address multiple Critical vulnerabilities affecting Windows, Mac OS X, ChromeOS, and Linux users.
newswww.securityweek.comJul 12, 2016, 5:04 PM- Week in review: Smart TV ransomware, DNC hack, and DAO under attackHelp Net Security
Here’s an overview of some of last week’s most interesting news and articles: Ransomware targets Android smart TVs If you own a Sharp and Philips smart TV running the Android TV OS, you should know that it could be hit by FLocker, a device-locking ransomware that targets both Android-powered mobile devices and smart TVs. 50% of ads on free livestreaming websites are malicious Many users of free livestreaming websites may be aware that the video … More →
newswww.helpnetsecurity.comJun 20, 2016, 12:00 PM - Adobe patches Flash Zero-Day exploited by ScarCruft APTSecurity Affairs
Adobe Flash Player 22.0.0.192 release fixes the Flash Player zero-day vulnerability (CVE-2016-4171) exploited by the APT group dubbed ScarCruft. Adobe has issued the Flash Player 22.0.0.192, a release that fixes the Flash Player zero-day vulnerability (CVE-2016-4171) exploited by the APT group dubbed ScarCruft in attacks on high-profile targets. The Flash Player flaw CVE-2016-4171 affects versions 21.0.0.242 and earlier for […]
newssecurityaffairs.comJun 19, 2016, 1:29 PM - Security Affairs newsletter Round 65 – News of the weekSecurity Affairs
A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. First of all let inform you that at the #infosec16 SecurityAffairs was awarded as The Best European Personal Security Blog http://securityaffairs.co/wordpress/48202/breaking-news/securityaffairs-best-european-personal-security-blog.html How to bypass two-factor authentication with a text message WauchulaGhost targets ISIS Twitter Accounts and floods them with […]
newssecurityaffairs.comJun 19, 2016, 7:11 AM Adobe has patched the Flash Player zero-day vulnerability exploited by a relatively new advanced persistent threat (APT) group dubbed “ScarCruft” in attacks aimed at high-profile targets.
newswww.securityweek.comJun 17, 2016, 8:08 AM- Fix for actively exploited Flash Player 0day is out, patch ASAP!Help Net Security
Adobe has issued a patch for the Plash Player zero-day vulnerability (CVE-2016-4171) that is actively exploited by the ScarCruft APT group. The bug, discovered by Anton Ivanov of Kaspersky Labs, is being used in “limited, targeted attacks.” According to Kaspersky, the group has been spotted using zero-day exploits before, and is currently engaged in two major operations. “The first of them, Operation Daybreak, appears to have been launched by ScarCruft in March 2016 and employs … More →
newswww.helpnetsecurity.comJun 17, 2016, 12:59 AM - Adobe Flash zero-day actively exploited in targeted attacksHelp Net Security
A zero-day vulnerability affecting the latest version of Adobe Flash Player and all previous ones is being actively exploited in limited, targeted attacks, the company has announced on Tuesday. The flaw (CVE-2016-4171) exists in Adobe Flash Player and 21.0.0.242 and earlier versions for Windows, Macintosh, Linux, and Chrome OS, and can be exploited to cause a crash and potentially allow an attacker to take control of the affected system. Kaspersky Lab’s Costin Raiu offered some … More →
newswww.helpnetsecurity.comJun 15, 2016, 2:20 PM Security experts from Kaspersky Lab revealed that an APT group dubbed ScarCruft exploited the zero day vulnerability (CVE-2016-4171) in Adobe Flash Player. According to the experts from Kaspersky Lab, an APT group dubbed ScarCruft exploited a zero day vulnerability (CVE-2016-4171) in Adobe Flash Player. The group launched a series of attacks against high-profile targets against entities in […]
newssecurityaffairs.comJun 15, 2016, 2:15 PMAdobe Systems warned users Tuesday that an unpatched Flash Player vulnerability is currently being exploited in targeted attacks. The company expects to deliver a patch as soon as Thursday. The exploit was discovered by researchers from antivirus vendor Kaspersky Lab in attacks attributed to a cyberespionage group known in the security industry as ScarCruft. The […]
newswww.csoonline.comJun 15, 2016, 11:40 AMThe Flash Player zero-day vulnerability whose existence was brought to light on Tuesday by Adobe has been exploited by a relatively new advanced persistent threat (APT) group named by Kaspersky Lab “ScarCruft.”
newswww.securityweek.comJun 15, 2016, 7:28 AMAdobe states that the Flash Player zero-day vulnerability (CVE-2016-4171) has been exploited in targeted attacks. It will be fixed later this week. Once again Adobe Flash Player is the target of hackers in the wild. Adobe has released security updates for several of its products announcing that the fix for a critical Flash Player zero-day vulnerability […]
newssecurityaffairs.comJun 15, 2016, 6:05 AM- Flash Zero-Day Exploited in Targeted AttacksSecurityWeek
Adobe has released security updates for several of its products, but a critical Flash Player zero-day vulnerability exploited in targeted attacks will only be resolved later this week.
newswww.securityweek.comJun 14, 2016, 4:36 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2016-4156CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…
- CVE-2016-4155CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…
- CVE-2016-4154CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…
- CVE-2016-4153CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…
- CVE-2016-4152CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…
- CVE-2016-4151CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…