CVE-2016-1013
published 2016-04-09CVE-2016-1013: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on…
PriorityP270high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
22.81%
97.5th percentile
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air_desktop_runtime | <= 21.0.0.176 | — |
| adobe | air_sdk | <= 21.0.0.176 | — |
| adobe | air_sdk_compiler | <= 21.0.0.176 | — |
| adobe | flash_player | <= 11.2.202.577 | — |
| adobe | flash_player | <= 18.0.0.333 | — |
| adobe | flash_player | <= 21.0.0.197 | — |
| adobe | flash_player_desktop_runtime | <= 21.0.0.197 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The PoC exploit for this use-after-free is unreliable in some browsers and may require the Flash content to render in the foreground for an extended period (minutes) before crashing in release builds, but crashes immediately in debug builds of Flash — anomalous long-running Flash rendering activity may indicate exploitation attempts. ↗
- →The vulnerability is a use-after-free triggered via rendering the display based on multiple scripts in Adobe Flash Player; monitor for Flash Player crashes or abnormal process termination tied to display rendering. ↗
- →Target Adobe Flash Player versions below 18.0.0.343, 19.x–21.x below 21.0.0.213 (Windows/OS X), and below 11.2.202.616 (Linux) as vulnerable; presence of these versions in the environment indicates unpatched exposure. ↗
- ·The PoC crash reliability depends on heap layout — the freed object must be reallocated with a specific value to trigger the observable crash; exploitation reliability may vary significantly across environments and browser/Flash configurations. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-89vh-wwvw-xxh6: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-1031 [HIGH] CWE-416 GHSA-89vh-wwvw-xxh6: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1016, and CVE-2016-1017.
GHSA
GHSA-7v4g-vc2q-829q: Use-after-free vulnerability in the Transform object implementation in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-14·CVSS 8.8
CVE-2016-1016 [HIGH] CWE-416 GHSA-7v4g-vc2q-829q: Use-after-free vulnerability in the Transform object implementation in Adobe Flash Player before 18
Use-after-free vulnerability in the Transform object implementation in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via a flash.geom.Matrix callback, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1017, and CVE-2016-1031.
GHSA
GHSA-vh5c-rcpj-3744: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-14·CVSS 8.8
CVE-2016-1013 [HIGH] CWE-416 GHSA-vh5c-rcpj-3744: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031.
GHSA
GHSA-4wrp-m389-3rjm: Use-after-free vulnerability in the LoadVars
ghsa_unreviewed·2022-05-14·CVSS 8.8
CVE-2016-1017 [HIGH] CWE-416 GHSA-4wrp-m389-3rjm: Use-after-free vulnerability in the LoadVars
Use-after-free vulnerability in the LoadVars.decode function in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1016, and CVE-2016-1031.
GHSA
GHSA-6j5q-5p93-ghjx: Use-after-free vulnerability in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-14·CVSS 8.8
CVE-2016-1011 [HIGH] CWE-416 GHSA-6j5q-5p93-ghjx: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1013, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031.
OSV
CVE-2016-1031: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1031 [HIGH] CVE-2016-1031: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1016, and CVE-2016-1017.
OSV
CVE-2016-1016: Use-after-free vulnerability in the Transform object implementation in Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1016 [HIGH] CVE-2016-1016: Use-after-free vulnerability in the Transform object implementation in Adobe Flash Player before 18
Use-after-free vulnerability in the Transform object implementation in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via a flash.geom.Matrix callback, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1017, and CVE-2016-1031.
OSV
CVE-2016-1011: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1011 [HIGH] CVE-2016-1011: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1013, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031.
OSV
CVE-2016-1013: Use-after-free vulnerability in Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1013 [HIGH] CVE-2016-1013: Use-after-free vulnerability in Adobe Flash Player before 18
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031.
OSV
CVE-2016-1017: Use-after-free vulnerability in the LoadVars
osv·2016-04-09·CVSS 8.8
CVE-2016-1017 [HIGH] CVE-2016-1017: Use-after-free vulnerability in the LoadVars
Use-after-free vulnerability in the LoadVars.decode function in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1016, and CVE-2016-1031.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1031 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1016, and CVE-2016-1017.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1017 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Use-after-free vulnerability in the LoadVars.decode function in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1016, and CVE-2016-1031.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1013 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1011 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1013, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1016 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Use-after-free vulnerability in the Transform object implementation in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via a flash.geom.Matrix callback, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1017, and CVE-2016-1031.
No detection rules found.
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0610.htmlhttp://www.securityfocus.com/bid/85926http://www.securitytracker.com/id/1035509https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-050https://helpx.adobe.com/security/products/flash-player/apsb16-10.htmlhttps://www.exploit-db.com/exploits/39778/http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0610.htmlhttp://www.securityfocus.com/bid/85926http://www.securitytracker.com/id/1035509https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-050https://helpx.adobe.com/security/products/flash-player/apsb16-10.htmlhttps://www.exploit-db.com/exploits/39778/
2016-04-09
Published