CVE-2016-1017: Use After Free
Use-after-free vulnerability in the LoadVars.decode function in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1016, and CVE-2016-1031.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1017?
CVE-2016-1017 is classified as a critical severity vulnerability that can allow attackers to execute arbitrary code.
How do I fix CVE-2016-1017?
To mitigate CVE-2016-1017, you should update Adobe Flash Player to version 18.0.0.343 or later, or to 21.0.0.213 or later.
Which versions of Adobe Flash Player are affected by CVE-2016-1017?
Versions of Adobe Flash Player earlier than 18.0.0.343 and 19.x through 21.x before 21.0.0.213 are affected by CVE-2016-1017.
What platforms are vulnerable to CVE-2016-1017?
CVE-2016-1017 affects Adobe Flash Player on Windows, macOS, and Linux systems.
What type of vulnerability is CVE-2016-1017?
CVE-2016-1017 is a use-after-free vulnerability that can lead to arbitrary code execution.