CVE-2016-0984
CVE-2016-0984
In short
A use-after-free vulnerability in Adobe Flash Player and AIR allows attackers to execute arbitrary code on Windows, macOS, and Linux systems. This occurs when the software tries to use memory that has already been freed, potentially allowing attackers to take complete control of the affected computer.
Technical detail
Use-after-free vulnerability (CWE-416) in Adobe Flash Player (versions before 18.0.0.329, 19.x/20.x before 20.0.0.306 on Windows/macOS, before 11.2.202.569 on Linux) and Adobe AIR/AIR SDK/AIR SDK & Compiler (before 20.0.0.260) exploitable via unspecified vectors to achieve arbitrary code execution. The vulnerability requires user interaction to trigger the vulnerable code path.
Summary generated and translated by AI from the official description.
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0983.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/39462/unverifiedexploitdbwww.exploit-db.com/exploits/39462unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0166.htmlhttps://helpx.adobe.com/security/products/flash-player/apsb16-04.htmlhttps://security.gentoo.org/glsa/201603-07https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0984https://www.exploit-db.com/exploits/39462/http://www.securitytracker.com/id/1034970