Junglewise Threat Intelligence

CVE-2016-0984: Adobe Flash Player and AIR Use-After-Free Vulnerability

CVE-2016-0984 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-05-25

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

A use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows remote attackers to execute arbitrary code via unspecified vectors. The vulnerability is distinct from other concurrent CVEs and has been observed being exploited in the wild.

Affected products

  • Adobe Flash Player before 18.0.0.329, 19.x and 20.x before 20.0.0.306
  • Adobe AIR before 20.0.0.260
  • Adobe AIR SDK before 20.0.0.260
  • Adobe AIR SDK & Compiler before 20.0.0.260

Timeline

  • 2016-02-09: patched: Adobe released security bulletin APSB16-04.
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-05-25: disclosed

Related threats