CVE-2016-1010
Adobe Flash Player and AIR Integer Overflow Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 19.40% probability · 97th percentile
- CISA KEV
- Listed 25 May 2022 · due 15 June 2022
- Weakness
- CWE-190
- Affected
- adobe/flash player · adobe/air · adobe/air sdk · samsung/x14j firmware · adobe/flash player desktop runtime · adobe/air desktop runtime · adobe/air sdk \& compiler
- Source
- psirt@adobe.com
CISA notes
The impacted products are end-of-life and should be disconnected if still in use. https://nvd.nist.gov/vuln/detail/CVE-2016-1010
References
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/84308Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035251Broken Link, Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/201603-07Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/84308Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035251Broken Link, Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/flash-player/apsb16-08.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/201603-07Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-1010US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.