CVE-2016-1015: Critical severity macromedia flash player vulnerability
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code by overriding NetConnection object properties to leverage an unspecified "type confusion," a different vulnerability than CVE-2016-1019.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1015?
CVE-2016-1015 has a critical severity rating due to the potential for arbitrary code execution.
How do I fix CVE-2016-1015?
To fix CVE-2016-1015, you should update Adobe Flash Player to the latest version, specifically beyond version 21.0.0.213.
Which Adobe Flash Player versions are affected by CVE-2016-1015?
CVE-2016-1015 affects Adobe Flash Player versions prior to 18.0.0.343 and 19.x through 21.x before 21.0.0.213.
Is CVE-2016-1015 exploitable on Linux systems?
Yes, CVE-2016-1015 is exploitable on Linux systems running affected versions of Adobe Flash Player.
What type of vulnerability is CVE-2016-1015?
CVE-2016-1015 is characterized as a type confusion vulnerability that allows attackers to execute arbitrary code.