Executive brief
An integer overflow vulnerability in Adobe Flash Player, AIR, and AIR SDK allows remote attackers to execute arbitrary code via unspecified vectors. The vulnerability was reported as being exploited in the wild and is included in CISA's Known Exploited Vulnerabilities catalog.
Affected products
- Adobe Flash Player before 18.0.0.324, 19.x and 20.x before 20.0.0.267 on Windows and OS X, before 11.2.202.559 on Linux
- Adobe AIR before 20.0.0.233
- Adobe AIR SDK before 20.0.0.233
- Adobe AIR SDK & Compiler before 20.0.0.233
Timeline
- 2015-12-28: advisory: Original Adobe security advisory APSB16-01 published.
- 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
- 2022-05-25: disclosed