cbcvebase.
CVE-2016-1013
published 2016-04-09

CVE-2016-1013: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on…

PriorityP270high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
22.81%
97.5th percentile
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031.

Affected

7 ranges
VendorProductVersion rangeFixed in
adobeair_desktop_runtime<= 21.0.0.176
adobeair_sdk<= 21.0.0.176
adobeair_sdk_compiler<= 21.0.0.176
adobeflash_player<= 11.2.202.577
adobeflash_player<= 18.0.0.333
adobeflash_player<= 21.0.0.197
adobeflash_player_desktop_runtime<= 21.0.0.197

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39778.zip
  • The PoC exploit for this use-after-free is unreliable in some browsers and may require the Flash content to render in the foreground for an extended period (minutes) before crashing in release builds, but crashes immediately in debug builds of Flash — anomalous long-running Flash rendering activity may indicate exploitation attempts.
  • The vulnerability is a use-after-free triggered via rendering the display based on multiple scripts in Adobe Flash Player; monitor for Flash Player crashes or abnormal process termination tied to display rendering.
  • Target Adobe Flash Player versions below 18.0.0.343, 19.x–21.x below 21.0.0.213 (Windows/OS X), and below 11.2.202.616 (Linux) as vulnerable; presence of these versions in the environment indicates unpatched exposure.
  • ·The PoC crash reliability depends on heap layout — the freed object must be reallocated with a specific value to trigger the observable crash; exploitation reliability may vary significantly across environments and browser/Flash configurations.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.