Skip to content
COOEY

EXPOSURES › CVE-2016-4117

CVE-2016-4117

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-4117 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatchednegligence

Adobe Flash Player's end-of-life status left unpatched RCE vulnerabilities perpetually exploitable, exemplifying the catastrophic risk of shipping and maintaining obsolete software.

Adobe Flash Player reached end-of-life in December 2020 without further security patches, leaving all remaining installations perpetually vulnerable to unpatched exploits. DIB organizations must care because maintaining obsolete software creates a perpetual security liability that can be exploited for remote code execution, directly impacting compliance with NIST 800-171 requirements for patch management and vulnerability mitigation. Organizations should immediately remove all legacy software and enforce strict software inventory controls to avoid similar negligence.

Shame score — Shipping and maintaining a discontinued product with known, unpatched RCE vulnerabilities demonstrates severe negligence and a failure to manage software lifecycles responsibly.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized