First published: Thu Apr 07 2016(Updated: )
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | ||
All of | ||
Adobe Flash Player | <=21.0.0.197 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
All of | ||
Macromedia Flash Player | <=18.0.0.333 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
All of | ||
Macromedia Flash Player | <=21.0.0.197 | |
Any of | ||
Apple iOS and macOS | ||
Chrome OS | ||
Linux Kernel | ||
Microsoft Windows Operating System | ||
All of | ||
Macromedia Flash Player | <=21.0.0.197 | |
Windows 10 | ||
All of | ||
Macromedia Flash Player | <=21.0.0.197 | |
Any of | ||
Windows 10 | ||
Microsoft Windows | ||
All of | ||
Macromedia Flash Player | <=11.2.202.577 | |
Linux Kernel | ||
All of | ||
Adobe AIR | <=21.0.0.176 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
All of | ||
Adobe AIR | <=21.0.0.176 | |
Any of | ||
iPhone OS | ||
Apple iOS and macOS | ||
Android | ||
Microsoft Windows Operating System | ||
All of | ||
Adobe AIR SDK & Compiler | <=21.0.0.176 | |
Any of | ||
iPhone OS | ||
Apple iOS and macOS | ||
Android | ||
Microsoft Windows Operating System | ||
Adobe Flash Player | <=21.0.0.197 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
Macromedia Flash Player | <=18.0.0.333 | |
Macromedia Flash Player | <=21.0.0.197 | |
Chrome OS | ||
Linux Kernel | ||
Macromedia Flash Player | <=21.0.0.197 | |
Windows 10 | ||
Macromedia Flash Player | <=21.0.0.197 | |
Microsoft Windows | ||
Macromedia Flash Player | <=11.2.202.577 | |
Adobe AIR | <=21.0.0.176 | |
Adobe AIR | <=21.0.0.176 | |
iPhone OS | ||
Android | ||
Adobe AIR SDK & Compiler | <=21.0.0.176 |
The impacted product is end-of-life and should be disconnected if still in use.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1019 is classified as a critical vulnerability that can result in denial of service or potential arbitrary code execution.
To mitigate CVE-2016-1019, users should upgrade Adobe Flash Player to version 21.0.0.198 or later.
Affected versions include Adobe Flash Player 21.0.0.197 and earlier.
Yes, CVE-2016-1019 can be exploited remotely by attackers to crash the application or execute arbitrary code.
There are no known workarounds for CVE-2016-1019; updating to the fixed version is the recommended approach.