Skip to content
COOEY

EXPOSURES › CVE-2016-4171

CVE-2016-4171

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-4171 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatchednegligence

Adobe Flash Player's end-of-life status left unpatched RCE vulnerabilities perpetually exploitable, exemplifying the catastrophic risk of shipping and maintaining obsolete software.

Adobe Flash Player reached end-of-life in December 2020 without further security updates, leaving all installed instances perpetually vulnerable to unpatched exploits. DIB organizations must care because maintaining obsolete software creates a perpetual security liability that can be exploited for remote code execution, directly impacting compliance with NIST 800-171 requirements for patch management and vulnerability mitigation. Organizations should immediately remove all legacy software and enforce strict application whitelisting to prevent exploitation of unpatched vulnerabilities.

Shame score — Adobe's failure to patch known vulnerabilities after reaching end-of-life demonstrates extreme negligence, as maintaining obsolete software creates a perpetual security liability that is easily exploitable and directly impacts compliance with NIST 800-171 patch management requirements.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Unspecified vulnerability in Adobe Flash Player allows for remote code execution.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized