Executive brief
An integer overflow vulnerability in Adobe Flash Player and AIR allows remote attackers to execute arbitrary code via unspecified vectors. The vulnerability is confirmed to have been exploited in the wild and affects multiple platforms including Windows, OS X, and Linux.
Affected products
- Adobe Flash Player before 18.0.0.333, 19.x through 21.x before 21.0.0.182
- Adobe AIR before 21.0.0.176
- Adobe AIR SDK before 21.0.0.176
- Adobe AIR SDK & Compiler before 21.0.0.176
Timeline
- 2016-03-10: patched: Adobe released security bulletin APSB16-08 addressing the issue.
- 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.