EXPOSURES › CVE-2016-7855
CVE-2016-7855
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, and the product's end-of-life status left it perpetually unpatched.
Adobe Flash Player suffered a use-after-free vulnerability enabling remote code execution, but its December 2020 end-of-life meant no patches existed to mitigate the exploit. DIB organizations must ensure all legacy software is fully retired to avoid exposure to actively exploited vulnerabilities that bypass modern defenses.
Shame score — Adobe shipped a product with known critical vulnerabilities for years before discontinuing it, and the end-of-life status left installations perpetually vulnerable to exploits that were actively weaponized in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |