CVE-2016-1019 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 22.3% (pctl 98)
Patch first
On CISA KEV — known exploited in the wild, due 2022-03-24.
Description
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 22.32% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | yes — remediate by 2022-03-24 |
| Public exploit | none known |
| Published | 2016-04-07 |
| Last modified | 2026-08-14 |
CISA KEV
| Name | Adobe Flash Player Arbitrary Code Execution Vulnerability |
|---|---|
| Added | 2022-03-03 |
| Due | 2022-03-24 |
| Vendor / product | Adobe / Flash Player |
| Ransomware use | known |
Affected (13)
| Vendor | Product |
|---|---|
| adobe | air desktop runtime |
| adobe | air sdk |
| adobe | air sdk \& compiler |
| adobe | flash player |
| adobe | flash player desktop runtime |
| apple | iphone os |
| apple | mac os x |
| android | |
| chrome os | |
| linux | linux kernel |
| microsoft | windows |
| microsoft | windows 10 |
| microsoft | windows 8.1 |
References
- http://blogs.adobe.com/psirt/?p=1330
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00012.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00055.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.html
- http://rhn.redhat.com/errata/RHSA-2016-0610.html
- http://www.securityfocus.com/bid/85856
- http://www.securitytracker.com/id/1035491
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-050
- https://helpx.adobe.com/security/products/flash-player/apsa16-01.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-10.html
- https://security.gentoo.org/glsa/201606-08
- https://www.fireeye.com/blog/threat-research/2016/04/cve-2016-1019_a_new.html
- http://blogs.adobe.com/psirt/?p=1330
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00012.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00055.html
→ the Explorer · watch your stack · NVD