Executive brief
A use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows remote attackers to execute arbitrary code via unspecified vectors. The vulnerability is distinct from other concurrent CVEs and has been observed being exploited in the wild.
Affected products
- Adobe Flash Player before 18.0.0.329, 19.x and 20.x before 20.0.0.306
- Adobe AIR before 20.0.0.260
- Adobe AIR SDK before 20.0.0.260
- Adobe AIR SDK & Compiler before 20.0.0.260
Timeline
- 2016-02-09: patched: Adobe released security bulletin APSB16-04.
- 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-05-25: disclosed