CVE-2016-0984highunder attackCWE-416

CVE-2016-0984

Published · Updated

83Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 55%
from disclosure to weapon7 days
Published on NVDFeb 10
1st PoC+7d
CISA KEV+2296d
exploitation probability
55%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
5 products
Red Hat Enterprise Linux Desktop Supplementary (v. 5) · Red Hat Enterprise Linux Desktop Supplementary (v. 6) · Red Hat Enterprise Linux Server Supplementary (v. 5) · Red Hat Enterprise Linux Server Supplementary (v. 6) · Red Hat Enterprise Linux Workstation Supplementary (v. 6)
Action required by CISAfederal deadline: 2022-06-15

The impacted products are end-of-life and should be disconnected if still in use.

In short

A use-after-free vulnerability in Adobe Flash Player and AIR allows attackers to execute arbitrary code on Windows, macOS, and Linux systems. This occurs when the software tries to use memory that has already been freed, potentially allowing attackers to take complete control of the affected computer.

Technical detail

Use-after-free vulnerability (CWE-416) in Adobe Flash Player (versions before 18.0.0.329, 19.x/20.x before 20.0.0.306 on Windows/macOS, before 11.2.202.569 on Linux) and Adobe AIR/AIR SDK/AIR SDK & Compiler (before 20.0.0.260) exploitable via unspecified vectors to achieve arbitrary code execution. The vulnerability requires user interaction to trigger the vulnerable code path.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0983.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.