Description Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the Action Message Format serialization (AFM0). Successful exploitation could lead to arbitrary code execution.
Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Published: Dec. 15, 2016
Modified: Nov. 17, 2022
Error type identifier: CWE-416 Fixed packages References to Advisories, Solutions, and Tools Affected configurations: cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:*
Running on/with:
cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
Running on/with:
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:*
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:*
Running on/with:
cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
Running on/with:
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:*
Running on/with:
cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
Running on/with:
cpe:2.3:o:google:chrome_os:-:*:*:*:*:*:*:*
Running on/with:
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Running on/with:
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
Running on/with:
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*