Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
https://security.gentoo.org/glsa/201606-08
http://rhn.redhat.com/errata/RHSA-2016-1079.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00047.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00046.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html
https://services.google.com/fh/files/misc/apt37-reaper-the-overlooked-north-korean-actor.pdf
https://blog.talosintelligence.com/2018/01/korea-in-crosshairs.html
https://github.com/hybridious/CVE-2016-4117
https://github.com/amit-raut/CVE-2016-4117-Report
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-4117
https://helpx.adobe.com/security/products/flash-player/apsb16-15.html
https://helpx.adobe.com/security/products/flash-player/apsa16-02.html
https://github.com/cisagov/vulnrichment/issues/196