Junglewise Threat Intelligence

CVE-2016-1010: Adobe Flash Player and AIR Integer Overflow Vulnerability

CVE-2016-1010 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-05-25

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

An integer overflow vulnerability in Adobe Flash Player and AIR allows remote attackers to execute arbitrary code via unspecified vectors. The vulnerability is confirmed to have been exploited in the wild and affects multiple platforms including Windows, OS X, and Linux.

Affected products

  • Adobe Flash Player before 18.0.0.333, 19.x through 21.x before 21.0.0.182
  • Adobe AIR before 21.0.0.176
  • Adobe AIR SDK before 21.0.0.176
  • Adobe AIR SDK & Compiler before 21.0.0.176

Timeline

  • 2016-03-10: patched: Adobe released security bulletin APSB16-08 addressing the issue.
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats