CVE-2016-1010: Adobe Flash Player and AIR Integer Overflow Vulnerability
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.
Other sources
Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Since the impacted Adobe Flash Player and Adobe AIR products are end-of-life, disconnect them from the network if they are still in use to reduce exposure.
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1010?
CVE-2016-1010 has a critical severity level that can lead to remote code execution in affected Adobe Flash Player and AIR versions.
How do I fix CVE-2016-1010?
To fix CVE-2016-1010, update Adobe Flash Player and AIR to the latest versions, specifically versions 18.0.0.334 or 21.0.0.182 and above.
Which versions of Adobe Flash Player are affected by CVE-2016-1010?
Adobe Flash Player versions prior to 18.0.0.334 for Windows, OS X, and Linux, as well as 19.x through 21.x before 21.0.0.182 are affected by CVE-2016-1010.
Are there any alternatives to Adobe Flash Player due to CVE-2016-1010?
Yes, users can consider transitioning to HTML5 or other modern web technologies, which do not rely on Flash and are more secure.
What platforms are affected by CVE-2016-1010?
CVE-2016-1010 affects Adobe Flash Player and AIR on Windows, macOS, Linux, and specific versions of Adobe AIR SDK.