First published: Thu Apr 07 2016(Updated: )
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | ||
All of | ||
Adobe Flash Player | <=21.0.0.197 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows | ||
All of | ||
Adobe Acrobat Reader | <=18.0.0.333 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows | ||
All of | ||
Adobe Acrobat Reader | <=21.0.0.197 | |
Any of | ||
Apple iOS and macOS | ||
Chrome OS | ||
Linux Kernel | ||
Microsoft Windows | ||
All of | ||
Adobe Acrobat Reader | <=21.0.0.197 | |
Microsoft Windows 10 | ||
All of | ||
Adobe Acrobat Reader | <=21.0.0.197 | |
Any of | ||
Microsoft Windows 10 | ||
Microsoft Windows 8.1 | ||
All of | ||
Adobe Acrobat Reader | <=11.2.202.577 | |
Linux Kernel | ||
All of | ||
Adobe AIR | <=21.0.0.176 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows | ||
All of | ||
Adobe AIR | <=21.0.0.176 | |
Any of | ||
iOS | ||
Apple iOS and macOS | ||
Android | ||
Microsoft Windows | ||
All of | ||
Adobe AIR SDK & Compiler | <=21.0.0.176 | |
Any of | ||
iOS | ||
Apple iOS and macOS | ||
Android | ||
Microsoft Windows | ||
Adobe Flash Player | <=21.0.0.197 | |
Apple iOS and macOS | ||
Microsoft Windows | ||
Adobe Acrobat Reader | <=18.0.0.333 | |
Adobe Acrobat Reader | <=21.0.0.197 | |
Chrome OS | ||
Linux Kernel | ||
Adobe Acrobat Reader | <=21.0.0.197 | |
Microsoft Windows 10 | ||
Adobe Acrobat Reader | <=21.0.0.197 | |
Microsoft Windows 8.1 | ||
Adobe Acrobat Reader | <=11.2.202.577 | |
Adobe AIR | <=21.0.0.176 | |
Adobe AIR | <=21.0.0.176 | |
iOS | ||
Android | ||
Adobe AIR SDK & Compiler | <=21.0.0.176 |
The impacted product is end-of-life and should be disconnected if still in use.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1019 is classified as a critical vulnerability that can result in denial of service or potential arbitrary code execution.
To mitigate CVE-2016-1019, users should upgrade Adobe Flash Player to version 21.0.0.198 or later.
Affected versions include Adobe Flash Player 21.0.0.197 and earlier.
Yes, CVE-2016-1019 can be exploited remotely by attackers to crash the application or execute arbitrary code.
There are no known workarounds for CVE-2016-1019; updating to the fixed version is the recommended approach.