⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: The impacted product is end-of-life and should be disconnected if still in use.. Due date: 2022-03-24.

CVE-2016-1019

13 documents10 sources
Severity
9.8CRITICAL
EPSS
71.4%
top 1.28%
CISA KEV
KEVRansomware
Added 2022-03-03
Due 2022-03-24
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedApr 7
KEV addedMar 3
KEV dueMar 24
Latest updateMay 14
CISA Required Action: The impacted product is end-of-life and should be disconnected if still in use.

Description

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages6 packages

NVDadobe/flash_player18.0.0.333+2
Ubuntuflashplugin-nonfree< 11.2.202.616ubuntu0.14.04.1
NVDadobe/air_sdk21.0.0.176

Patches

🔴Vulnerability Details

4
GHSA
GHSA-mj28-pj3c-6jwr: Adobe Flash Player 212022-05-14
CVEList
CVE-2016-1019: Adobe Flash Player 212016-04-07
OSV
CVE-2016-1019: Adobe Flash Player 212016-04-07
VulnCheck
Adobe Flash Player Arbitrary Code Execution Vulnerability2016

📋Vendor Advisories

3
CISA
Adobe Flash Player Arbitrary Code Execution Vulnerability2022-03-03
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-102016-04-07
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-102016-04-07

🕵️Threat Intelligence

4
Talos
News Flash! Another Adobe Flash Zero-day Vulnerability Spotted in the Wild2016-04-07
Talos
News Flash! Another Adobe Flash Zero-day Vulnerability Spotted in the Wild2016-04-07
Qualys
Update: Adobe to release patch for 0-day in Flash Player | Qualys2016-04-06
Qualys
Update: Adobe to release patch for 0-day in Flash Player | Qualys2016-04-06

💬Community

1
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-102016-04-06
CVE-2016-1019 (CRITICAL CVSS 9.8) | Adobe Flash Player 21.0.0.197 and e | cvebase.io