CVE-2016-1019: Adobe Flash Player Arbitrary Code Execution Vulnerability
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
Other sources
Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If Adobe Flash Player 21.0.0.197 (and earlier) is still in use, disconnect it from the network because the impacted product is end-of-life.
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1019?
CVE-2016-1019 is classified as a critical vulnerability that can result in denial of service or potential arbitrary code execution.
How do I fix CVE-2016-1019?
To mitigate CVE-2016-1019, users should upgrade Adobe Flash Player to version 21.0.0.198 or later.
What versions of Adobe Flash Player are affected by CVE-2016-1019?
Affected versions include Adobe Flash Player 21.0.0.197 and earlier.
Can CVE-2016-1019 be exploited remotely?
Yes, CVE-2016-1019 can be exploited remotely by attackers to crash the application or execute arbitrary code.
Is there a workaround for CVE-2016-1019?
There are no known workarounds for CVE-2016-1019; updating to the fixed version is the recommended approach.