ZeroHour

CVE-2016-1010

KEVmass

Integer Overflow RCE in Adobe Flash Player and AIR

CISA: Adobe Flash Player and AIR Integer Overflow Vulnerability

CVSS 3.1
8.8 high
EPSS
19%p97
Published
()
KEV added
AI analysis

CVE-2016-1010 is an integer overflow (CWE-190) in Adobe Flash Player and Adobe AIR that allows attackers to execute arbitrary code via unspecified vectors, most plausibly by inducing a user to open attacker-supplied Flash content, consistent with the user-interaction requirement in its CVSS 3.1 score of 8.8. It affects Flash Player before 18.0.0.333 (Extended Support Release) and 19.x through 21.x before 21.0.0.182 on Windows and OS X, Flash Player before 11.2.202.577 on Linux, and Adobe AIR, AIR SDK, and AIR SDK & Compiler releases before 21.0.0.176, with Samsung X14J firmware also listed as an affected bundler of the Flash component. Successful exploitation yields arbitrary code execution in the context of the Flash runtime, typically sufficient to install malware or move laterally under the user's privileges. Anyone still running these now end-of-life runtimes, including embedded deployments such as the Samsung X14J firmware, is exposed. CISA added the flaw to the KEV catalog on 2022-05-25, and related reporting ties Windows zero-day Flash exploitation to targeted attacks by the FruityArmor APT, indicating in-the-wild exploitation; EPSS assigns a 19.4% probability of exploitation within 30 days (97th percentile), though no public PoC is known.

What to do: Upgrade Flash Player to 18.0.0.333 (ESR), 21.0.0.182 (Windows/OS X), or 11.2.202.577 (Linux), and Adobe AIR, AIR SDK, and AIR SDK & Compiler to 21.0.0.176. Since all impacted products are end-of-life, CISA's required action is to disconnect them if still in use; prioritize removing or disabling Flash/AIR entirely and verify that no embedded deployments (e.g., Samsung X14J firmware) still rely on Flash. Hunt for signs of targeted exploitation consistent with FruityArmor APT activity, such as unexpected Flash content and suspicious child processes spawned from browsers or Flash-enabled applications.

Affected
Adobe Flash Player (Windows and OS X)19.x through 21.x before 21.0.0.182; also before 18.0.0.333 (Extended Support Release)
Adobe Flash Player (Linux)before 11.2.202.577
Adobe Flash Player Desktop Runtimebefore 18.0.0.333 (ESR); 19.x through 21.x before 21.0.0.182 on Windows and OS X; before 11.2.202.577 on Linux
Adobe AIR (Desktop Runtime)before 21.0.0.176
Adobe AIR SDKbefore 21.0.0.176
Adobe AIR SDK & Compilerbefore 21.0.0.176
samsung X14J firmware
Estimated exposure
masson the order of hundreds of millions of desktop installations at the time of disclosure (Flash was near-universal on PCs); a far smaller, shrinking legacy base… — Adobe Flash Player was installed on the vast majority of internet-connected desktops in 2016, with additional exposure from bundled AIR runtimes and embedded Flash in products such as Samsung X14J firmware, but Flash reached end-of-life in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player and AIR
Required action
The impacted products are end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
adobesamsung
Products
flash player, air, air sdk, x14j firmware, flash player desktop runtime, air desktop runtime, air sdk \& compiler
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news