CVE-2016-1019
published 2016-04-07CVE-2016-1019: Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via…
PriorityP185critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
22.49%
97.4th percentile
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air_desktop_runtime | <= 21.0.0.176 | — |
| adobe | air_sdk | <= 21.0.0.176 | — |
| adobe | air_sdk_compiler | <= 21.0.0.176 | — |
| adobe | flash_player | <= 11.2.202.577 | — |
| adobe | flash_player | <= 18.0.0.333 | — |
| adobe | flash_player | <= 21.0.0.197 | — |
| adobe | flash_player_desktop_runtime | <= 21.0.0.197 | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
Snort Rules: 38429-38434
- →CVE-2016-1019 was actively exploited in the Nuclear and Magnitude exploit kits; detections should cover Flash content delivered via these EK infrastructure patterns. ↗
- →Flash Player versions 21.0.0.197 and earlier (including ESR 18.0.0.333 and earlier, and version 20.0.0.306) are vulnerable; Flash 21.0.0.182 and later contain a mitigation but ESR 18.0 branch does NOT include it — prioritize detection/blocking for ESR 18.0 branch users. ↗
- →The RATANKBA campaign used malicious JavaScript injected into watering-hole websites to fingerprint browser components and load Flash exploits (CVE-2016-1019) from attacker-controlled C&C/payload-hosting infrastructure. ↗
- →A malicious SWF file (detected as SWF_EXPLOYT.YYRQ) was hosted on compromised sites alongside RATANKBA payloads; hunt for .swf files with this detection name or similar exploit-kit-staged SWF delivery. ↗
- ·Adobe introduced a mitigation for CVE-2016-1019 in Flash 21.0.0.182 (released March 10, 2016), but this mitigation is NOT present in the ESR 18.0 branch — ESR users remain fully exploitable even on the latest ESR build. ↗
- ·Systems running Flash Player 21.0.0.182 or later have a built-in mitigation that prevents the known exploitation technique for CVE-2016-1019, but upgrading to 21.0.0.213 (APSB16-10) is still required for full remediation. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Adobe Flash Player Arbitrary Code Execution Vulnerability
cisa·2022-03-03·CVSS 9.8
CVE-2016-1019 [CRITICAL] Adobe Flash Player Arbitrary Code Execution Vulnerability
Vulnerability: Adobe Flash Player Arbitrary Code Execution Vulnerability
Affected: Adobe Flash Player
Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-1019
Remediation Due Date: 2022-03-24
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1015 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code by overriding NetConnection object properties to leverage an unspecified "type confusion," a different vulnerability than CVE-2016-1019.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 9.8
CVE-2016-1019 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
VulDB
Adobe Flash Player 21.0.0.197 memory corruption (APSA16-01 / Nessus ID 90505)
vuldb·2026-04-23·CVSS 9.8
CVE-2016-1019 [CRITICAL] Adobe Flash Player 21.0.0.197 memory corruption (APSA16-01 / Nessus ID 90505)
A vulnerability, which was classified as very critical, has been found in Adobe Flash Player 21.0.0.197. This impacts an unknown function. This manipulation causes memory corruption.
This vulnerability is tracked as CVE-2016-1019. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is advisable to upgrade the affected component.
GHSA
GHSA-qxr5-2c92-fj86: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-14·CVSS 9.8
CVE-2016-1015 [CRITICAL] CWE-843 GHSA-qxr5-2c92-fj86: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code by overriding NetConnection object properties to leverage an unspecified "type confusion," a different vulnerability than CVE-2016-1019.
GHSA
GHSA-mj28-pj3c-6jwr: Adobe Flash Player 21
ghsa_unreviewed·2022-05-14
CVE-2016-1019 [CRITICAL] GHSA-mj28-pj3c-6jwr: Adobe Flash Player 21
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
OSV
CVE-2016-1015: Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1015 [HIGH] CVE-2016-1015: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code by overriding NetConnection object properties to leverage an unspecified "type confusion," a different vulnerability than CVE-2016-1019.
OSV
CVE-2016-1019: Adobe Flash Player 21
osv·2016-04-07·CVSS 9.8
CVE-2016-1019 [CRITICAL] CVE-2016-1019: Adobe Flash Player 21
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
VulnCheck
Adobe Flash Player Arbitrary Code Execution Vulnerability
vulncheck·2016·CVSS 9.8
CVE-2016-1019 [CRITICAL] Adobe Flash Player Arbitrary Code Execution Vulnerability
Adobe Flash Player Arbitrary Code Execution Vulnerability
Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.
Affected: Adobe Flash Player
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Known Ransomware Campaign Use: Known
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cve.org/CVERecord?id=CVE-2016-1019; https://blog.trendmicro.com/trendlabs-security-intelligence/locky-ransomware-spreads-flash-windows-kernel-exploits/; https://unit42.paloaltonetworks.com/unit42-dealerschoice-sofacys-flash-player-exploit-platform/; https://www.welivesecurity.com/2016/12/06/readers-popular-websites-targeted-stealthy-steg
No detection rules found.
No public exploits indexed.
Qualys
The Rise of Ransomware
blogs_qualys·2021-10-05
The Rise of Ransomware
## Table of Contents
Ransomware Infection Vectors
Ransomware Attacks and Exact CVEs To Prioritize for Monitoring
Unified View of Critical Ransomware Risk Exposures
Qualys Ransomware Risk Assessment & Remediation Service
Continuous detection & prioritization for Ransomware-specific vulnerabilities withVMDR
DiscoverandPrioritizeRansomware Vulnerabilities
Discover and Mitigate RansomwareMisconfigurationssuch as SMB, Insecure RDP
Automated Proactive & Reactive Patching for Ransomware vulnerabilities
Ready to Learn more and see for yourself?
Resources
References
With most employees still working from remote locations, ransomware attacks have increased steadily since the early months of the Covid-19 pandemic. According to the FBI’s 2020 Internet Crime Report 2400+ ransomware-related
Trendmicro
RATANKBA: Delving into Large-scale Watering Holes
blogs_trendmicro·2017-02-27
RATANKBA: Delving into Large-scale Watering Holes
Malware
## RATANKBA: Delving into Large-scale Watering Holes
We provide further analysis and insights regarding the RATANKBA malware, which was tied to malware attacks against banks in Poland, but also in a string of similar incidents involving financial institutions in different countries.
By: Trend Micro 2017/02/27 Read time: ( words)
Save to Folio
In early February, several financial organizations reported malware infection on their workstations, apparently coming from legitimate websites. The attacks turned out to be part of a large-scale campaign to compromise trusted websites in order to infect the systems of targeted enterprises across various industries. The strategy is typically known as a “ watering hole ” attack.
It was all sparked by a spate of recent malware attacks on P
Trendmicro
RATANKBA: Delving into Large-scale Watering Holes
blogs_trendmicro·2017-02-27
RATANKBA: Delving into Large-scale Watering Holes
Malware
# RATANKBA: Delving into Large-scale Watering Holes
We provide further analysis and insights regarding the RATANKBA malware, which was tied to malware attacks against banks in Poland, but also in a string of similar incidents involving financial institutions in different countries.
By: Trend Micro
2017/02/27
Read time: ( words)
Save to Folio
In early February, several financial organizations reported malware infection on their workstations, apparently coming from legitimate websites. The attacks turned out to be part of a large-scale campaign to compromise trusted websites in order to infect the systems of targeted enterprises across various industries. The strategy is typically known as a “watering hole” attack.
It was all sparked by a spate of recent malware attacks on Pol
Trendmicro
RATANKBA: Delving into Large-scale Watering Holes
blogs_trendmicro·2017-02-27
RATANKBA: Delving into Large-scale Watering Holes
Malware
## RATANKBA: Delving into Large-scale Watering Holes
We provide further analysis and insights regarding the RATANKBA malware, which was tied to malware attacks against banks in Poland, but also in a string of similar incidents involving financial institutions in different countries.
By: Trend Micro Feb 27, 2017 Read time: ( words)
Save to Folio
In early February, several financial organizations reported malware infection on their workstations, apparently coming from legitimate websites. The attacks turned out to be part of a large-scale campaign to compromise trusted websites in order to infect the systems of targeted enterprises across various industries. The strategy is typically known as a “ watering hole ” attack.
It was all sparked by a spate of recent malware attacks on
Zscaler
Top Exploit Kit Activity Roundup | Zscaler
blogs_zscaler·2016-06-24
Top Exploit Kit Activity Roundup | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Talos
News Flash! Another Adobe Flash Zero-day Vulnerability Spotted in the Wild
blogs_talos·2016-04-07·CVSS 9.8
CVE-2016-1019 [CRITICAL] News Flash! Another Adobe Flash Zero-day Vulnerability Spotted in the Wild
In today's threat landscape, Adobe Flash Player unfortunately remains an attractive attack vector for adversaries to exploit and compromise systems. Over the past year, Talos has observed several instances where adversaries have identified zero-day vulnerabilities and exploited them to compromise systems. Talos is aware of reports that CVE-2016-1019, an Adobe Flash 0-day vulnerability, is currently being exploited in the wild and is affecting systems running Windows 10 and earlier.
According to the Adobe Flash Player security advisory published on April 5, Flash Player versions 21.0.0.197 and earlier are susceptible to compromise via CVE-2016-1019. This includes Flash Player version 20.0.0.306 as well as Flash Player Extended Support Release (ESR) version 18.0.0.333 and earlier. One speci
Talos
News Flash! Another Adobe Flash Zero-day Vulnerability Spotted in the Wild
blogs_talos·2016-04-07·CVSS 9.8
CVE-2016-1019 [CRITICAL] News Flash! Another Adobe Flash Zero-day Vulnerability Spotted in the Wild
## News Flash! Another Adobe Flash Zero-day Vulnerability Spotted in the Wild
In today's threat landscape, Adobe Flash Player unfortunately remains an attractive attack vector for adversaries to exploit and compromise systems. Over the past year, Talos has observed several instances where adversaries have identified zero-day vulnerabilities and exploited them to compromise systems. Talos is aware of reports that CVE-2016-1019, an Adobe Flash 0-day vulnerability, is currently being exploited in the wild and is affecting systems running Windows 10 and earlier.
According to the Adobe Flash Player security advisory published on April 5, Flash Player versions 21.0.0.197 and earlier are susceptible to compromise via CVE-2016-1019. This includes Flash Player version 20.0.0.306 as well as Flash
Qualys
Update: Adobe to release patch for 0-day in Flash Player | Qualys
blogs_qualys·2016-04-06·CVSS 9.8
CVE-2016-1019 [CRITICAL] Update: Adobe to release patch for 0-day in Flash Player | Qualys
Update: Adobe has released a new version of its Flash Player in APSB16-10. It addresses 22 critical vulnerabilities which can be used to gain code execution and 2 vulnerabilities that can be retrieve memory address information and to bypass a security feature. One of the vulnerabilities CVE-2016-1019 is currently being attacked in the wild in Exploit Kits.
This release is Adobe’s April Patch Tuesday release. We do not expected another release this month. You should patch as quickly as possible, especially on machines that are still running a pre-March version of Flash as these are vulnerable to CVE-2016-1019.
Proofpoint’s security researcher Kafeine describes how the Magnitude Exploit Kit uses the vulnerability and why you should update as quickly as possible.
Original: Adobe announced
Qualys
Update: Adobe to release patch for 0-day in Flash Player | Qualys
blogs_qualys·2016-04-06·CVSS 9.8
CVE-2016-1019 [CRITICAL] Update: Adobe to release patch for 0-day in Flash Player | Qualys
Update : Adobe has released a new version of its Flash Player in APSB16-10 . It addresses 22 critical vulnerabilities which can be used to gain code execution and 2 vulnerabilities that can be retrieve memory address information and to bypass a security feature. One of the vulnerabilities CVE-2016-1019 is currently being attacked in the wild in Exploit Kits.
This release is Adobe’s April Patch Tuesday release. We do not expected another release this month. You should patch as quickly as possible, especially on machines that are still running a pre-March version of Flash as these are vulnerable to CVE-2016-1019.
Proofpoint’s security researcher Kafeine describes how the Magnitude Exploit Kit uses the vulnerability and why you should update as quickly as possible.
Original : Adobe announc
Zscaler
Zscaler discovers Flash Player Vulnerabilities | 04-12-2016
blogs_zscaler
Zscaler discovers Flash Player Vulnerabilities | 04-12-2016
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-10
bugzilla·2016-04-06·CVSS 8.1
CVE-2016-1019 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
A critical vulnerability (CVE-2016-1019) exists in Adobe Flash Player 21.0.0.197 and earlier versions for Windows, Macintosh, Linux, and Chrome OS. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.
https://helpx.adobe.com/security/products/flash-player/apsa16-01.html
Discussion:
Updates for Adobe Flash Player were released, further details are in the APSB16-10 bulletin.
Adobe Security Bulletin APSB16-10 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB16-10:
These updates harden a mitigation against JIT spraying attacks that could
http://blogs.adobe.com/psirt/?p=1330http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00055.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0610.htmlhttp://www.securityfocus.com/bid/85856http://www.securitytracker.com/id/1035491https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-050https://helpx.adobe.com/security/products/flash-player/apsa16-01.htmlhttps://helpx.adobe.com/security/products/flash-player/apsb16-10.htmlhttps://security.gentoo.org/glsa/201606-08https://www.fireeye.com/blog/threat-research/2016/04/cve-2016-1019_a_new.htmlhttp://blogs.adobe.com/psirt/?p=1330http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00055.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0610.htmlhttp://www.securityfocus.com/bid/85856http://www.securitytracker.com/id/1035491https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-050https://helpx.adobe.com/security/products/flash-player/apsa16-01.htmlhttps://helpx.adobe.com/security/products/flash-player/apsb16-10.htmlhttps://security.gentoo.org/glsa/201606-08https://www.fireeye.com/blog/threat-research/2016/04/cve-2016-1019_a_new.htmlhttps://github.com/cisagov/vulnrichment/issues/196https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-1019
2016-04-07
Published
2022-03-03
Added to CISA KEV
Exploited in the wild