cbcvebase.
CVE-2016-1019
published 2016-04-07

CVE-2016-1019: Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via…

PriorityP185critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
22.49%
97.4th percentile
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

Affected

7 ranges
VendorProductVersion rangeFixed in
adobeair_desktop_runtime<= 21.0.0.176
adobeair_sdk<= 21.0.0.176
adobeair_sdk_compiler<= 21.0.0.176
adobeflash_player<= 11.2.202.577
adobeflash_player<= 18.0.0.333
adobeflash_player<= 21.0.0.197
adobeflash_player_desktop_runtime<= 21.0.0.197

Detection & IOCsextracted from sources · hover to see the quote

porteye-watch[.]in:443
filenamenbt_scan.exe
snort
Snort Rules: 38429-38434
  • CVE-2016-1019 was actively exploited in the Nuclear and Magnitude exploit kits; detections should cover Flash content delivered via these EK infrastructure patterns.
  • Flash Player versions 21.0.0.197 and earlier (including ESR 18.0.0.333 and earlier, and version 20.0.0.306) are vulnerable; Flash 21.0.0.182 and later contain a mitigation but ESR 18.0 branch does NOT include it — prioritize detection/blocking for ESR 18.0 branch users.
  • The RATANKBA campaign used malicious JavaScript injected into watering-hole websites to fingerprint browser components and load Flash exploits (CVE-2016-1019) from attacker-controlled C&C/payload-hosting infrastructure.
  • A malicious SWF file (detected as SWF_EXPLOYT.YYRQ) was hosted on compromised sites alongside RATANKBA payloads; hunt for .swf files with this detection name or similar exploit-kit-staged SWF delivery.
  • ·Adobe introduced a mitigation for CVE-2016-1019 in Flash 21.0.0.182 (released March 10, 2016), but this mitigation is NOT present in the ESR 18.0 branch — ESR users remain fully exploitable even on the latest ESR build.
  • ·Systems running Flash Player 21.0.0.182 or later have a built-in mitigation that prevents the known exploitation technique for CVE-2016-1019, but upgrading to 21.0.0.213 (APSB16-10) is still required for full remediation.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.