cbcvebase.
CVE-2016-0984
published 2016-02-10

CVE-2016-0984: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux…

PriorityP188high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-06-15
Exploited in the wild
EPSS
55.38%
98.9th percentile
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0983.

Affected

8 ranges
VendorProductVersion rangeFixed in
adobeair_desktop_runtime<= 20.0.0.233
adobeair_sdk<= 20.0.0.233
adobeair_sdk_compiler<= 20.0.0.233
adobeflash_player<= 11.2.202.559
adobeflash_player<= 18.0.0.326
adobeflash_player<= 20.0.0.272
adobeflash_player<= 20.0.0.286
adobeflash_player_desktop_runtime<= 20.0.0.286

Detection & IOCsextracted from sources · hover to see the quote

hash4a49135d2ecc07085a8b7c5925a36c0a
ip89.45.67.107
urlhxxp://89.45.67[.]107/rss/5uzosoff0u.iaf
urlhxxp://89.45.67[.]107/rss/mo.exe
pathC:\ProgramData\ManagerApp\AdapterTroubleshooter.exe
pathC:\ProgramData\ManagerApp\15b937.cab
pathC:\ProgramData\ManagerApp\install.cab
pathC:\ProgramData\ManagerApp\msvcr90.dll
pathC:\ProgramData\ManagerApp\d3d9.dll
processwinlogon
  • CVE-2016-0984 was exploited in the wild by BlackOasis APT as a zero-day in June 2015, delivering FinSpy payloads via exploit chains. Detections for related FinSpy/Flash exploit activity include PDM:Exploit.Win32.Generic, HEUR:Exploit.SWF.Generic, and HEUR:Exploit.MSOffice.Generic.
  • The Flash exploit (related campaign) uses a NOP sled composed of alternating 0x90 and 0x91 opcodes inside SWF files to evade AV detection of large NOP blocks. Consider scanning SWF files for this byte pattern.
  • The CVE-2016-0984 vulnerability is a use-after-free in Adobe Flash Player's Sound.loadPCMFromByteArray. A dangling pointer is created when a second call with a short ByteArray triggers an exception before the pointer is reset; the pointer is then readable via Sound.extract. Monitor for Flash processes crashing or spawning child processes.
  • The exploit chain delivers a Flash exploit embedded as an ActiveX object inside Office documents (.docx). Hunt for Office processes spawning Flash-related child processes or network connections.
  • ·The IOCs from the Kaspersky/Securelist report (IP 89.45.67.107, mo.exe hash, file paths) are primarily associated with the CVE-2017-11292 campaign by BlackOasis, not directly with CVE-2016-0984 itself. They are included because the source explicitly links BlackOasis to CVE-2016-0984 exploit chains delivering FinSpy, and the infrastructure/TTPs overlap.
  • ·The exploit-db PoC (39462.zip) is a proof-of-concept for the Sound.loadPCMFromByteArray dangling pointer bug underlying CVE-2016-0984. It demonstrates read-only dangling pointer access, not a full weaponized exploit.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.