CVE-2016-1010
KEVmassInteger Overflow RCE in Adobe Flash Player and AIR
CISA: Adobe Flash Player and AIR Integer Overflow Vulnerability
CVE-2016-1010 is an integer overflow (CWE-190) in Adobe Flash Player and Adobe AIR that allows attackers to execute arbitrary code via unspecified vectors, most plausibly by inducing a user to open attacker-supplied Flash content, consistent with the user-interaction requirement in its CVSS 3.1 score of 8.8. It affects Flash Player before 18.0.0.333 (Extended Support Release) and 19.x through 21.x before 21.0.0.182 on Windows and OS X, Flash Player before 11.2.202.577 on Linux, and Adobe AIR, AIR SDK, and AIR SDK & Compiler releases before 21.0.0.176, with Samsung X14J firmware also listed as an affected bundler of the Flash component. Successful exploitation yields arbitrary code execution in the context of the Flash runtime, typically sufficient to install malware or move laterally under the user's privileges. Anyone still running these now end-of-life runtimes, including embedded deployments such as the Samsung X14J firmware, is exposed. CISA added the flaw to the KEV catalog on 2022-05-25, and related reporting ties Windows zero-day Flash exploitation to targeted attacks by the FruityArmor APT, indicating in-the-wild exploitation; EPSS assigns a 19.4% probability of exploitation within 30 days (97th percentile), though no public PoC is known.
What to do: Upgrade Flash Player to 18.0.0.333 (ESR), 21.0.0.182 (Windows/OS X), or 11.2.202.577 (Linux), and Adobe AIR, AIR SDK, and AIR SDK & Compiler to 21.0.0.176. Since all impacted products are end-of-life, CISA's required action is to disconnect them if still in use; prioritize removing or disabling Flash/AIR entirely and verify that no embedded deployments (e.g., Samsung X14J firmware) still rely on Flash. Hunt for signs of targeted exploitation consistent with FruityArmor APT activity, such as unexpected Flash content and suspicious child processes spawned from browsers or Flash-enabled applications.
| Adobe Flash Player (Windows and OS X) | 19.x through 21.x before 21.0.0.182; also before 18.0.0.333 (Extended Support Release) |
| Adobe Flash Player (Linux) | before 11.2.202.577 |
| Adobe Flash Player Desktop Runtime | before 18.0.0.333 (ESR); 19.x through 21.x before 21.0.0.182 on Windows and OS X; before 11.2.202.577 on Linux |
| Adobe AIR (Desktop Runtime) | before 21.0.0.176 |
| Adobe AIR SDK | before 21.0.0.176 |
| Adobe AIR SDK & Compiler | before 21.0.0.176 |
| samsung X14J firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.
- Affected
- Adobe Flash Player and AIR
- Required action
- The impacted products are end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown