Junglewise Threat Intelligence

CVE-2016-1019: Adobe Flash Player Arbitrary Code Execution Vulnerability

CVE-2016-1019 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-03

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors. The vulnerability was exploited in the wild as a zero-day before being patched.

Affected products

  • Adobe Flash Player 21.0.0.197 and earlier

Timeline

  • 2016-04: exploited: Exploited in the wild in April 2016.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats