March 3, 2022 · Applied Cybernetics Group
CVE-2016-4117 — Adobe Flash Player
Adobe Flash Player Arbitrary Code Execution Vulnerability
- Added to KEV
2022-03-03- Federal due date
2022-03-24- Vendor
- Adobe
- Product
- Flash Player
- EPSS
- 99.8th percentile (score 0.930, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2016-4117
CISA short description
An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.
Required action
The impacted product is end-of-life and should be disconnected if still in use.