CVE-2016-0984
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
The impacted products are end-of-life and should be disconnected if still in use.
A use-after-free vulnerability in Adobe Flash Player and AIR allows attackers to execute arbitrary code on Windows, macOS, and Linux systems. This occurs when the software tries to use memory that has already been freed, potentially allowing attackers to take complete control of the affected computer.
Use-after-free vulnerability (CWE-416) in Adobe Flash Player (versions before 18.0.0.329, 19.x/20.x before 20.0.0.306 on Windows/macOS, before 11.2.202.569 on Linux) and Adobe AIR/AIR SDK/AIR SDK & Compiler (before 20.0.0.260) exploitable via unspecified vectors to achieve arbitrary code execution. The vulnerability requires user interaction to trigger the vulnerable code path.
The full analysis of this CVE is available in Portuguese →