ZeroHour
Security Affairspublished ()ingested @securityaffairs

Adobe fixes CVE-2016-1019 Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-8439
Dereferenced Pointer Vulnerability in Adobe Flash Player Allows Code Execution

CVE-2014-8439 is a memory-safety flaw (CWE-119) in Adobe Flash Player caused by the program's mishandling of a dereferenced memory pointer, allowing access to memory outside the intended bounds. As is typical of Flash memory-corruption bugs, it is triggered when Flash Player processes maliciously crafted content (e.g., a hostile .swf file rendered in a browser or embedded Flash player), which can crash the player or, more seriously, allow attacker-controlled code execution. A successful attacker gains the ability to run arbitrary code with the privileges of the logged-in user, a common route to workstation compromise and follow-on malware deployment. All Adobe Flash Player deployments were in scope at the time of the 2014 disclosure (the source data provides no version range), and because Flash reached end-of-life in December 2020, the population plausibly at risk today consists mainly of unmanaged or legacy endpoints, embedded/bundled enterprise applications, and installations still loading Flash content. Exploitation is confirmed in the wild: CISA added this CVE to the Known Exploited Vulnerabilities catalog on May 25, 2022, and its EPSS score of 20% (97th percentile) indicates a meaningful probability of ongoing or renewed exploitation despite the product's age.

Do: Because Flash Player is end-of-life (since December 31, 2020) and no longer receives security updates, follow CISA's required action: uninstall Flash Player and any remaining browser plugins, or disconnect/isolate systems where it cannot yet be removed, and inventory third-party, intranet, and embedded applications that bundle Flash. Where Flash must remain temporarily, ensure the final release is installed (its post-EOL kill switch blocks most Flash content from running after January 12, 2021, which limits this attack vector), restrict Flash content to trusted sources, and prioritize monitoring given the KEV listing and 20% EPSS score.

20% KEV
  • Adobe Flash Player
masson the order of millions of legacy/embedded installations worldwide (Flash historically had 1 billion+ installs; residual post-EOL count unknown)
CVE-2015-0310
ASLR Protection-Mechanism Bypass in Adobe Flash Player

CVE-2015-0310 is a protection-mechanism weakness in Adobe Flash Player in which the player fails to properly restrict the discovery of memory addresses, allowing an attacker to defeat Address Space Layout Randomization (ASLR), the mitigation that randomizes where code and data are loaded in memory. It is triggered by running attacker-controlled Flash (SWF) content in a browser, ActiveX control, or embedded player, typically as part of an exploit chain in which the attacker infers module addresses during a heap spray. The flaw grants no code execution by itself; its value to attackers is that it makes memory-corruption exploits deterministic and reliable, and it is generally chained with another Flash vulnerability to achieve remote code execution. Any system still running Adobe Flash Player is affected, a product now end-of-life, so exposure is concentrated in legacy enterprise web applications, kiosks, embedded players, and browser/OS builds that shipped with Flash bundled. CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2022-05-25, confirming exploitation in the wild; no public proof-of-concept is known, no CVSS score has been published, and EPSS estimates a 15.2% chance of exploitation within 30 days (97th percentile).

Do: Per CISA's required action, treat Flash as retired: inventory all systems for Flash usage (browser plugins, IE/ActiveX controls, standalone players, and embedded enterprise applications) and remove or disconnect it where found. Where Flash must remain, ensure the latest available Adobe release is installed and restrict execution to trusted SWF content, prioritizing internet-facing endpoints given the KEV listing.

15% KEV
  • Adobe Flash Player
mass~1M-10M+ endpoints still running Flash in legacy enterprise apps, kiosks, or bundled-browser contexts
CVE-2016-0984
Use-After-Free RCE in Adobe Flash Player and AIR

Adobe Flash Player and Adobe AIR contain a use-after-free memory corruption flaw (CWE-416) that allows remote attackers to execute arbitrary code by persuading a user to load specially crafted Flash content, as the CVSS vector (AV:N/UI:R) indicates exploitation via user interaction such as opening a malicious SWF in a browser or an application embedding Flash/AIR. Successful exploitation gives the attacker code execution with the victim user's privileges, with high impact on confidentiality, integrity, and availability. All Flash Player versions before 18.0.0.329, 19.x/20.x before 20.0.0.306 on Windows and OS X, and before 11.2.202.569 on Linux are affected, along with Adobe AIR Desktop Runtime, AIR SDK, and AIR SDK & Compiler before 20.0.0.260. The flaw was fixed in February 2016 as one of several sibling use-after-free bugs (CVE-2016-0973, -0974, -0975, -0982, -0983), and a public proof of concept is available (Exploit-DB 39462). CISA added it to the Known Exploited Vulnerabilities catalog on 2022-05-25, confirming known in-the-wild exploitation (ransomware use unknown), and EPSS at 54.8% (99th percentile) indicates continued likelihood of exploitation against remaining exposed systems.

Do: Upgrade Flash Player to 18.0.0.329, or 20.0.0.306 on Windows/macOS and 11.2.202.569 on Linux, and upgrade AIR, AIR SDK, and AIR SDK & Compiler to 20.0.0.260. Because Flash is end-of-life, per CISA KEV guidance the preferred action is to remove or disable Flash entirely and disconnect any system still running it; audit legacy browsers, kiosks, industrial HMIs, and embedded apps that still load SWF content, since exploitation requires user-opened Flash content.

8.855% KEV PoC
  • Adobe Flash Player All versions before 18.0.0.329; 19.x and 20.x before 20.0.0.306 on Windows and OS X; before 11.2.202.569 on Linux
  • Adobe Flash Player Desktop Runtime All versions before 18.0.0.329; 19.x and 20.x before 20.0.0.306 on Windows and OS X; before 11.2.202.569 on Linux
  • Adobe AIR Desktop Runtime Before 20.0.0.260
  • +2 more
massApproximately 1 billion+ installations at the time of disclosure (Flash was installed on the vast majority of internet-connected PCs in early 2016); current…
CVE-2016-0998
+1 in the same advisory: …1001
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linu

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0999, and CVE-2016-1000.

NVD description · AI analysis pending
8.830% PoC ×2
  • adobe flash player
  • adobe air
  • adobe air sdk
  • +1 more
CVE-2016-1010
Integer Overflow RCE in Adobe Flash Player and AIR

CVE-2016-1010 is an integer overflow (CWE-190) in Adobe Flash Player and Adobe AIR that allows attackers to execute arbitrary code via unspecified vectors, most plausibly by inducing a user to open attacker-supplied Flash content, consistent with the user-interaction requirement in its CVSS 3.1 score of 8.8. It affects Flash Player before 18.0.0.333 (Extended Support Release) and 19.x through 21.x before 21.0.0.182 on Windows and OS X, Flash Player before 11.2.202.577 on Linux, and Adobe AIR, AIR SDK, and AIR SDK & Compiler releases before 21.0.0.176, with Samsung X14J firmware also listed as an affected bundler of the Flash component. Successful exploitation yields arbitrary code execution in the context of the Flash runtime, typically sufficient to install malware or move laterally under the user's privileges. Anyone still running these now end-of-life runtimes, including embedded deployments such as the Samsung X14J firmware, is exposed. CISA added the flaw to the KEV catalog on 2022-05-25, and related reporting ties Windows zero-day Flash exploitation to targeted attacks by the FruityArmor APT, indicating in-the-wild exploitation; EPSS assigns a 19.4% probability of exploitation within 30 days (97th percentile), though no public PoC is known.

Do: Upgrade Flash Player to 18.0.0.333 (ESR), 21.0.0.182 (Windows/OS X), or 11.2.202.577 (Linux), and Adobe AIR, AIR SDK, and AIR SDK & Compiler to 21.0.0.176. Since all impacted products are end-of-life, CISA's required action is to disconnect them if still in use; prioritize removing or disabling Flash/AIR entirely and verify that no embedded deployments (e.g., Samsung X14J firmware) still rely on Flash. Hunt for signs of targeted exploitation consistent with FruityArmor APT activity, such as unexpected Flash content and suspicious child processes spawned from browsers or Flash-enabled applications.

8.819% KEV
  • Adobe Flash Player (Windows and OS X) 19.x through 21.x before 21.0.0.182; also before 18.0.0.333 (Extended Support Release)
  • Adobe Flash Player (Linux) before 11.2.202.577
  • Adobe Flash Player Desktop Runtime before 18.0.0.333 (ESR); 19.x through 21.x before 21.0.0.182 on Windows and OS X; before 11.2.202.577 on Linux
  • +4 more
masson the order of hundreds of millions of desktop installations at the time of disclosure (Flash was near-universal on PCs); a far smaller, shrinking legacy base…
CVE-2016-1019
Arbitrary code execution flaw in Adobe Flash Player, used in ransomware attacks

CVE-2016-1019 is a remotely exploitable flaw in Adobe Flash Player that lets an attacker cause a denial of service or, in the worst case, execute arbitrary code on the victim's system. It is triggered remotely, typically when a user views malicious Flash content delivered through a web browser, an application, or a document that embeds Flash content. A successful attack runs code with the privileges of the logged-on user, making the bug a useful foothold for deploying malware, including ransomware. Anyone still running Adobe Flash Player is potentially affected - the product is end-of-life (support ended December 31, 2020), but it persists on legacy desktops, intranet applications, kiosks, and embedded or industrial systems; the CISA data does not list specific affected version ranges. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on March 3, 2022, notes known ransomware use, and EPSS assigns a 22.5% probability of exploitation in the next 30 days (98th percentile), though no public proof-of-concept is catalogued.

Do: Per CISA's required action, disconnect or remove any system still running Adobe Flash Player, since the product is end-of-life and receives no further security updates; the bug was patched in Adobe's 2016 updates, so only long-unupdated or embedded Flash installs remain vulnerable. Uninstall Flash from browsers and legacy software and confirm that no internal applications or sites still serve or require SWF content. Because exploitation is tied to ransomware campaigns, prioritize user workstations and any internet-facing host with Flash installed.

9.822% KEV ransomware
  • Adobe Flash Player
mass≈ millions of legacy endpoints worldwide (Flash historically ran on ~99% of internet-connected PCs; current residual install count unknown)
Full article466 words · extracted from securityaffairs.com · click to collapse

Cyber criminals are exploiting the Flash player zero-day vulnerability (CVE-2016-1019) affecting Flash Player 21.0.0.197 and earlier disclosed by Adobe.

Cyber criminals are already exploiting the Flash player zero-day vulnerability (CVE-2016-1019) affecting Flash Player 21.0.0.197 and earlier (CVE-2016-1019) disclosed by Adobe this week.

Researchers at security firm Proofpoint confirmed that cyber gangs are exploiting it to distribute a ransomware dubbed Cerber.

The hackers exploited the Flash Zero-day vulnerability to infect machines running Flash Player 20.0.0.306 and earlier on Windows 10 and earlier.

“A critical vulnerability (CVE-2016-1019) exists in Adobe Flash Player 21.0.0.197 and earlier versions for Windows, Macintosh, Linux, and Chrome OS. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.” reported the advisory published by Adobe a couple of days ago on the Flash Player zero-day vulnerability.

The Flash player zero-day vulnerability is a memory corruption bug that exists in an undocumented ASnative API, it can be exploited by attackers for remote code execution. The popular security expert Kafeine reported the inclusion of the zero-day flaw in the Magnitude exploit kit.

“On April 2, 2016, Proofpoint researchers discovered that the Magnitude exploit kit (EK) [1] was successfully exploiting Adobe Flash version 20.0.0.306. Because the Magnitude EK in question did not direct any exploits to Flash 21.0.0.182, we initially suspected that the exploit was for CVE-2016-1001 as in Angler [2], the combination exploit “CVE-2016-0998/CVE-2016-0984″ [3], or CVE-2016-1010.” reported ProofPoint.

“Despite the fact that this new exploit could potentially work on any version of Adobe Flash, including a fully patched instance of Flash, the threat actors implemented it in a manner that only targeted older versions of Flash. In other words, equipped with a weapon that could pierce even the latest armor, they only used it against old armor, and in doing so exposed to security researchers a previously unreported vulnerability,” states Proofpoint “We refer to this type of faulty implementation as a ‘degraded’ mode, and it is something that we have observed in the past with CVE-2014-8439 and CVE-2015-0310 in Angler.”

Adobe explained that a mitigation was had been in the version 21.0.0.182 released in March, anyway it has solved the issue with the release of Flash Player 21.0.0.213, which also fixes other 23 vulnerabilities.

It is interesting to note that experts at FireEye noted that the zero-day exploit code for the CVE-2016-1019 presents many similarities to exploits leaked as a result of the clamorous Hacking Team hack.

“The exploit’s code layout and some of the functionalities are similar to the leaked HackingTeam exploits, in that it downloads malware from another server and executes it.” states the analysis published by FireEye.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – Flash Player zero-day vulnerability, CVE-2016-1019)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/46107/malware/adobe-fixes-cve-2016-1019.html