CVE-2016-1010
published 2016-03-12CVE-2016-1010: Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe…
PriorityP181high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-06-15
Exploited in the wild
EPSS
19.79%
97.1th percentile
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 20.0.0.233 | — |
| adobe | air_desktop_runtime | <= 20.0.0.260 | — |
| adobe | air_sdk | <= 20.0.0.260 | — |
| adobe | air_sdk_compiler | <= 20.0.0.260 | — |
| adobe | flash_player | <= 20.0.0.306 | — |
| adobe | flash_player | <= 11.2.202.569 | — |
| adobe | flash_player_desktop_runtime | <= 20.2.2.306 | — |
| samsung | x14j_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The exploit delivery chain consists of three Flash objects; the vulnerability-triggering code is located in the second SWF file delivered to the victim. ↗
- →The attack infrastructure redirects victims to a server controlled by the attackers located in Poland; browser fingerprinting checks are performed before the redirect. ↗
- →Attackers exploit a bug in the Windows Dynamic Data Exchange (DDE) component to bypass security solutions as part of the CVE-2016-1010 exploitation chain. ↗
- →Kaspersky's Automatic Exploit Prevention (AEP) component proactively blocks this attack; AEP detections can serve as a hunt signal. ↗
- →Initial infection vector is spear-phishing emails pointing to a hacked website hosting the exploit; hunt for inbound links to compromised sites delivering SWF content. ↗
- ·CVE-2016-1010 is an integer overflow in Adobe Flash Player; affected versions are Flash Player before 18.0.0.333, 19.x–21.x before 21.0.0.182 (Windows/OS X), before 11.2.202.577 (Linux), and Adobe AIR/AIR SDK/AIR SDK & Compiler before 21.0.0.176. ↗
- ·The vulnerability was actively exploited in the wild by the ScarCruft APT group (Operation Daybreak) before the patch was released; it was a zero-day at time of exploitation. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Flash Player up to 20.0.0.306 numeric error (APSB16-08 / Nessus ID 89868)
vuldb·2026-04-23·CVSS 8.8
CVE-2016-1010 [HIGH] Adobe Flash Player up to 20.0.0.306 numeric error (APSB16-08 / Nessus ID 89868)
A vulnerability marked as critical has been reported in Adobe Flash Player up to 11.2.202.569/18.0.0.329/20.0.0.233/20.0.0.260/20.0.0.306. Affected by this vulnerability is an unknown functionality. The manipulation leads to numeric error.
This vulnerability is listed as CVE-2016-1010. The attack may be initiated remotely. In addition, an exploit is available.
It is suggested to upgrade the affected component.
GHSA
GHSA-3r99-gh2f-23fp: Integer overflow in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0993 [HIGH] CWE-190 GHSA-3r99-gh2f-23fp: Integer overflow in Adobe Flash Player before 18
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-1010.
GHSA
GHSA-54f2-vwh2-6c3h: Integer overflow in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-0963 [HIGH] CWE-190 GHSA-54f2-vwh2-6c3h: Integer overflow in Adobe Flash Player before 18
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0993 and CVE-2016-1010.
GHSA
GHSA-rf44-cp45-ppcv: Integer overflow in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-1010 [HIGH] CWE-190 GHSA-rf44-cp45-ppcv: Integer overflow in Adobe Flash Player before 18
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.
OSV
CVE-2016-1010: Integer overflow in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-1010 [HIGH] CVE-2016-1010: Integer overflow in Adobe Flash Player before 18
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.
OSV
CVE-2016-0993: Integer overflow in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0993 [HIGH] CVE-2016-0993: Integer overflow in Adobe Flash Player before 18
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-1010.
OSV
CVE-2016-0963: Integer overflow in Adobe Flash Player before 18
osv·2016-03-12·CVSS 8.8
CVE-2016-0963 [HIGH] CVE-2016-0963: Integer overflow in Adobe Flash Player before 18
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0993 and CVE-2016-1010.
VulnCheck
Adobe Flash Player and AIR Integer Overflow Vulnerability
vulncheck·2016·CVSS 8.8
CVE-2016-1010 [HIGH] CWE-190 Adobe Flash Player and AIR Integer Overflow Vulnerability
Adobe Flash Player and AIR Integer Overflow Vulnerability
Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code.
Affected: Adobe Flash Player and AIR
Required Action: The impacted products are end-of-life and should be disconnected if still in use.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://dl.acm.org/doi/pdf/10.1145/3465481.3465758; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-06-15
CISA
Adobe Flash Player and AIR Integer Overflow Vulnerability
cisa·2022-05-25·CVSS 8.8
CVE-2016-1010 [HIGH] CWE-190 Adobe Flash Player and AIR Integer Overflow Vulnerability
Vulnerability: Adobe Flash Player and AIR Integer Overflow Vulnerability
Affected: Adobe Flash Player and AIR
Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code.
Required Action: The impacted products are end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-1010
Remediation Due Date: 2022-06-15
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0963 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0993 and CVE-2016-1010.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-1010 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-08
vendor_redhat·2016-03-10·CVSS 8.8
CVE-2016-0993 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-1010.
No detection rules found.
Securelist
Kaspersky Security Bulletin 2016. Review of the year. Overall statistics for 2016
blogs_securelist·2016-12-14
Kaspersky Security Bulletin 2016. Review of the year. Overall statistics for 2016
Table of Contents
- Introduction
- Six things we learned this year that we didn’t know before
- Other top threats
- The impact on business
Authors
- Kaspersky
## Executive Summary
Download Review of the year
Download Overall statistics
Download the consolidated Kaspersky Security Bulletin 2016
1. Kaspersky Security Bulletin. Predictions for 2017
2. Kaspersky Security Bulletin 2016. The ransomware revolution
## Introduction
If they were asked to sum up 2016 in a single word, many people around the world – particularly those in Europe and the US – might choose the word ‘unpredictable’. On the face of it, the same could apply to cyberthreats in 2016: the massive botnets of connected devices that paralysed much of the Internet in October; the relentless hacking of high profile websit
Securelist
Kaspersky Security Bulletin 2016. Review of the year. Overall statistics for 2016
blogs_securelist·2016-12-14
Kaspersky Security Bulletin 2016. Review of the year. Overall statistics for 2016
Table of Contents
Introduction
Six things we learned this year that we didn’t know before
1. That the underground economy is more sophisticated and bigger than ever: xDedic – the shady marketplace
2. That the biggest financial heist did not involve a stock exchange: the SWIFT-enabled transfers
3. That critical infrastructure is worryingly vulnerable: the BlackEnergy attacks
4. That a targeted attack can have no pattern: the ProjectSauron APT
5. That the online release of vast volumes of data can be an influential tactic: ShadowBrokers and other data dumps
6. That a camera could be part of a global cyber-army: the insecure Internet of Things
Other top threats
Inventive APTs
New zero-days
The hunt for financial gain
The ultimate vulnerability: people
Mobile advertising
The imp
Securelist
Windows zero-day exploit used in targeted attacks by FruityArmor APT
blogs_securelist·2016-10-20·CVSS 7.8
CVE-2016-3393 [HIGH] Windows zero-day exploit used in targeted attacks by FruityArmor APT
Table of Contents
Attack chain description
EOP zero-day details
Authors
Anton Ivanov
A few days ago, Microsoft published the “critical” MS16-120 security bulletin with fixes for vulnerabilities in Microsoft Windows, Microsoft Office, Skype for Business, Silverlight and Microsoft Lync.
One of the vulnerabilities – CVE-2016-3393 – was reported to Microsoft by Kaspersky Lab in September 2016.
Here’s a bit of background on how this zero-day was discovered. A few of months ago, we deployed a new set of technologies in our products to identify and block zero-day attacks. These technologies proved their effectiveness earlier this year, when we discovered two Adobe Flash zero-day exploits – CVE-2016-1010 and CVE-2016-4171. Two Windows EoP exploits have also been found with the help of this
Securelist
Windows zero-day exploit used in targeted attacks by FruityArmor APT
blogs_securelist·2016-10-20·CVSS 7.8
CVE-2016-3393 [HIGH] Windows zero-day exploit used in targeted attacks by FruityArmor APT
Table of Contents
- Attack chain description
- EOP zero-day details
Authors
- Anton Ivanov
A few days ago, Microsoft published the “critical” MS16-120 security bulletin with fixes for vulnerabilities in Microsoft Windows, Microsoft Office, Skype for Business, Silverlight and Microsoft Lync.
One of the vulnerabilities – CVE-2016-3393 – was reported to Microsoft by Kaspersky Lab in September 2016.
Here’s a bit of background on how this zero-day was discovered. A few of months ago, we deployed a new set of technologies in our products to identify and block zero-day attacks. These technologies proved their effectiveness earlier this year, when we discovered two Adobe Flash zero-day exploits – CVE-2016-1010 and CVE-2016-4171. Two Windows EoP exploits have also been found with the help of
Securelist
IT threat evolution in Q2 2016. Overview
blogs_securelist·2016-08-11
IT threat evolution in Q2 2016. Overview
Table of Contents
- Targeted attacks and malware campaigns
- Malware stories
- Data breaches
Authors
- David Emm
- Roman Unuchek
Download the full report (PDF)
## Targeted attacks and malware campaigns
### Cha-ching! Skimming off the cream
Earlier in the year, as part of an incident response investigation, we uncovered a new version of the Skimer ATM malware. The malware, which first surfaced in 2009, has been re-designed. So too have the tactics of the cybercriminals using it. The new ATM infector has been targeting ATMs around the world, including the UAE, France, the United States, Russia, Macau, China, the Philippines, Spain, Germany, Georgia, Poland, Brazil and the Czech Republic.
Rather than the well-established method of fitting a fake card-reader to the ATM, the attackers
Qualys
Patch Tuesday Update: Adobe Flash 0-day APSB16-08 | Qualys
blogs_qualys·2016-03-11·CVSS 8.8
CVE-2016-1010 [HIGH] Patch Tuesday Update: Adobe Flash 0-day APSB16-08 | Qualys
Today Adobe released an critical update for their Flash Player APSB16-08 that addresses 23 vulnerabilities. The update had been expected on Tuesday already, but had been held back due to the last-minute inclusion of CVE-2016-1010, a vulnerability that is currently under targeted attack in the wild. A successful exploit of this vulnerability gives the attacker Remote Code Execution on the target machine. Attack vector includes malicious websites set up for the purpose of attack using Search Engine Poisoning, “normal” websites that have been hacked and are under the control of the attacker, and e-mailed documents (Word, PDF) that include a malicious Flash component.
The vulnerability was found at Kaspersky Labs, by Anton Ivanov.
Microsoft also released this delayed Flash as an out-of-band
Qualys
Patch Tuesday Update: Adobe Flash 0-day APSB16-08 | Qualys
blogs_qualys·2016-03-10·CVSS 8.8
CVE-2016-1010 [HIGH] Patch Tuesday Update: Adobe Flash 0-day APSB16-08 | Qualys
Today Adobe released an critical update for their Flash Player APSB16-08 that addresses 23 vulnerabilities. The update had been expected on Tuesday already, but had been held back due to the last-minute inclusion of CVE-2016-1010, a vulnerability that is currently under targeted attack in the wild. A successful exploit of this vulnerability gives the attacker Remote Code Execution on the target machine. Attack vector includes malicious websites set up for the purpose of attack using Search Engine Poisoning, “normal” websites that have been hacked and are under the control of the attacker, and e-mailed documents (Word, PDF) that include a malicious Flash component.
The vulnerability was found at Kaspersky Labs, by Anton Ivanov.
Microsoft also released this delayed Flash as an out-of-band
Zscaler
Zscaler found Multiple Security Vulnerabilities | 03-11-2016
blogs_zscaler
Zscaler found Multiple Security Vulnerabilities | 03-11-2016
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-08
bugzilla·2016-03-11·CVSS 8.8
CVE-2016-0963 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-08
flash-plugin: multiple code execution issues fixed in APSB16-08
Adobe Security Bulletin APSB16-08 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB16-08:
These updates resolve integer overflow vulnerabilities that could lead to code execution (CVE-2016-0963, CVE-2016-0993, CVE-2016-1010).
These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, CVE-2016-1000).
These updates resolve a heap overflow vulnerability that could lead to code execution (CVE-2016-1001).
These updates resolve
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.htmlhttp://www.securityfocus.com/bid/84308http://www.securitytracker.com/id/1035251https://helpx.adobe.com/security/products/flash-player/apsb16-08.htmlhttps://security.gentoo.org/glsa/201603-07http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00032.htmlhttp://www.securityfocus.com/bid/84308http://www.securitytracker.com/id/1035251https://helpx.adobe.com/security/products/flash-player/apsb16-08.htmlhttps://security.gentoo.org/glsa/201603-07https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-1010
2016-03-12
Published
2022-05-25
Added to CISA KEV
Exploited in the wild