cbcvebase.
CVE-2016-1102
published 2016-05-11

CVE-2016-1102: Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and…

PriorityP263high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
EXPLOIT
EPSS
39.65%
98.4th percentile
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.

Affected

11 ranges
VendorProductVersion rangeFixed in
adobeair_desktop_runtime<= 21.0.0.198
adobeair_sdk<= 21.0.0.198
adobeair_sdk_compiler<= 21.0.0.198
adobeflash_player<= 21.0.0.241
adobeflash_player<= 18.0.0.343
adobeflash_player<= 11.2.202.616
adobeflash_player<= 21.0.0.216
adobeflash_player<= 21.0.0.213
adobeflash_player_desktop_runtime<= 21.0.0.226
microsoftinternet_explorer
microsoftinternet_explorer

Detection & IOCsextracted from sources · hover to see the quote

  • ·CVE-2016-1102 is described as an unspecified memory corruption vulnerability in Adobe Flash Player (before 18.0.0.352, 19.x–21.x before 21.0.0.242 on Windows/OS X, before 11.2.202.621 on Linux). No attack vectors, payloads, or exploitation details are publicly disclosed in the available sources.
  • ·CVE-2016-1102 is grouped with a broad set of memory corruption CVEs (CVE-2016-1096, CVE-2016-1098 through CVE-2016-1104, CVE-2016-4109 through CVE-2016-4163) all fixed in the same Adobe Flash release (APSB16-15). No distinguishing technical indicators are available to differentiate CVE-2016-1102 from the others in this batch.
  • ·The Exploit-DB entry (39824) covers a separate JXR out-of-bounds read issue in Adobe Flash and is not specifically attributed to CVE-2016-1102 in the source material. No concrete IOCs (hashes, URLs, commands) are extractable from the available sources for CVE-2016-1102.

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.