ZeroHour

CVE-2016-1019

KEV ransomwaremass

Arbitrary code execution flaw in Adobe Flash Player, used in ransomware attacks

CISA: Adobe Flash Player Arbitrary Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
22%p98
Published
()
KEV added
AI analysis

CVE-2016-1019 is a remotely exploitable flaw in Adobe Flash Player that lets an attacker cause a denial of service or, in the worst case, execute arbitrary code on the victim's system. It is triggered remotely, typically when a user views malicious Flash content delivered through a web browser, an application, or a document that embeds Flash content. A successful attack runs code with the privileges of the logged-on user, making the bug a useful foothold for deploying malware, including ransomware. Anyone still running Adobe Flash Player is potentially affected - the product is end-of-life (support ended December 31, 2020), but it persists on legacy desktops, intranet applications, kiosks, and embedded or industrial systems; the CISA data does not list specific affected version ranges. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on March 3, 2022, notes known ransomware use, and EPSS assigns a 22.5% probability of exploitation in the next 30 days (98th percentile), though no public proof-of-concept is catalogued.

What to do: Per CISA's required action, disconnect or remove any system still running Adobe Flash Player, since the product is end-of-life and receives no further security updates; the bug was patched in Adobe's 2016 updates, so only long-unupdated or embedded Flash installs remain vulnerable. Uninstall Flash from browsers and legacy software and confirm that no internal applications or sites still serve or require SWF content. Because exploitation is tied to ransomware campaigns, prioritize user workstations and any internet-facing host with Flash installed.

Affected
Adobe Flash Player
Estimated exposure
mass≈ millions of legacy endpoints worldwide (Flash historically ran on ~99% of internet-connected PCs; current residual install count unknown) — Estimated from Flash Player's near-universal historic desktop penetration and its continued presence in legacy browser installs, intranet web applications, kiosks, and embedded/industrial software despite its December 2020 end-of-life,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Known
Vendors
adobe
Products
flash player desktop runtime, flash player, air desktop runtime, air sdk, air sdk \& compiler
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news