---
id: CVE-2016-4117
title: >-
  Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute
  arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
summary: >-
  Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute
  arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: adobe
product: flash_player
affected:
  - flash_player <= 21.0.0.226
  - enterprise_linux_desktop = 5.0
  - enterprise_linux_desktop = 6.0
  - enterprise_linux_server = 5.0
  - enterprise_linux_server = 6.0
  - enterprise_linux_server_from_rhui = 5.0
  - enterprise_linux_server_from_rhui = 6.0
  - enterprise_linux_workstation = 5.0
  - enterprise_linux_workstation = 6.0
  - evergreen = 11.4
  - opensuse = 13.1
  - opensuse = 13.2
  - linux_enterprise_desktop = 12
  - linux_enterprise_workstation_extension = 12
published: '2016-05-11'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T04:17:30.760'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2016-4117'
references:
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html'
    label: psirt@adobe.com
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.html'
    label: psirt@adobe.com
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00046.html'
    label: psirt@adobe.com
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00047.html'
    label: psirt@adobe.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-1079.html'
    label: psirt@adobe.com
  - url: 'http://www.securityfocus.com/bid/90505'
    label: psirt@adobe.com
  - url: 'http://www.securitytracker.com/id/1035826'
    label: psirt@adobe.com
  - url: 'https://helpx.adobe.com/security/products/flash-player/apsa16-02.html'
    label: psirt@adobe.com
  - url: 'https://helpx.adobe.com/security/products/flash-player/apsb16-15.html'
    label: psirt@adobe.com
  - url: 'https://security.gentoo.org/glsa/201606-08'
    label: psirt@adobe.com
  - url: 'https://www.exploit-db.com/exploits/46339/'
    label: psirt@adobe.com
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00046.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00047.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-1079.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/90505'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1035826'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://helpx.adobe.com/security/products/flash-player/apsa16-02.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://helpx.adobe.com/security/products/flash-player/apsb16-15.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/201606-08'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/46339/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/cisagov/vulnrichment/issues/196'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-4117
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
  - score-dispute
exploited: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'no'
  technicalImpact: total
  timestamp: '2021-02-03T00:00:00+00:00'
scores:
  nvd: 9.8
  adp: 7.8
ingestedAt: '2026-09-10T14:26:36.765Z'
epss: 0.94354
epssPercentile: 0.99849
kev: true
kevDateAdded: '2022-03-03'
kevDueDate: '2022-03-24'
kevRansomware: true
exploits:
  exploitdb: true
  github: 1
  githubRepos:
    - 'https://github.com/amit-raut/CVE-2016-4117-Report'
  metasploit:
    - exploit/osx/browser/adobe_flash_delete_range_tl_op
  checkedAt: '2026-09-21T15:23:34.744Z'
---

## Overview

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

## Affected

- `flash_player <= 21.0.0.226`
- `enterprise_linux_desktop = 5.0`
- `enterprise_linux_desktop = 6.0`
- `enterprise_linux_server = 5.0`
- `enterprise_linux_server = 6.0`
- `enterprise_linux_server_from_rhui = 5.0`
- `enterprise_linux_server_from_rhui = 6.0`
- `enterprise_linux_workstation = 5.0`
- `enterprise_linux_workstation = 6.0`
- `evergreen = 11.4`
- `opensuse = 13.1`
- `opensuse = 13.2`
- `linux_enterprise_desktop = 12`
- `linux_enterprise_workstation_extension = 12`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
