Vulnerability record · CVE-2016-1010 · published 12 March 2016
CVE-2016-1010: Adobe Flash Player and AIR integer overflow allows code execution
Adobe · Flash Player
Adobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain an integer overflow (CWE-190) that permits arbitrary code execution via unspecified vectors. The flaw affects Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X, before 11.2.202.577 on Linux, and AIR/SDK builds before 21.0.0.176. It matters because the affected products are end-of-life and the issue is listed in CISA KEV.
Description
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 and confirmed exploitation via CISA KEV, tempered by the requirement for user interaction and the end-of-life status of the affected products.
What it is
Adobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain an integer overflow (CWE-190) that permits arbitrary code execution via unspecified vectors. The flaw affects Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X, before 11.2.202.577 on Linux, and AIR/SDK builds before 21.0.0.176. It matters because the affected products are end-of-life and the issue is listed in CISA KEV.
Impact
An attacker who triggers the overflow can execute arbitrary code in the context of the affected runtime, giving full compromise of confidentiality, integrity and availability per the CVSS vector. No privilege escalation beyond the runtime's own context is described.
Attack surface
The CVSS vector is network-reachable (AV:N) with low complexity and no privileges, but requires user interaction (UI:R), consistent with a victim opening crafted content in Flash Player or AIR. The description does not specify the exact vectors or delivery mechanism.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-05-25, indicating real-world exploitation; EPSS gives a 30-day probability of 0.194 (97th percentile). No ransomware campaign use is documented.
What to do
- Apply the vendor patch: upgrade Flash Player to 18.0.0.333 or later, 21.0.0.182 or later for 19.x-21.x, 11.2.202.577 or later on Linux, and AIR/AIR SDK/AIR SDK & Compiler to 21.0.0.176 or later.
- Because Flash Player and AIR are end-of-life, disconnect or remove the affected products where they are still in use, per CISA's required action.
- Block or disable Flash content in browsers and email clients, and restrict execution of AIR applications to trusted sources.
- Where removal is not immediately possible, isolate systems running the affected runtimes and restrict their network access.
Detection
- Hunt for hosts still running Flash Player or AIR versions below the fixed builds listed in Adobe APSB16-08.
- Monitor for processes loading Flash/AIR runtime libraries spawning unexpected child processes or making outbound connections.
- Review proxy and DNS logs for delivery of Flash content (.swf) from untrusted or newly registered domains.
- Check endpoint telemetry for crashes or memory corruption events in Flash Player or AIR processes that may indicate exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-1010 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Adobe Flash Player and AIR Integer Overflow Vulnerability". Required action: The impacted products are end-of-life and should be disconnected if still in use. Federal deadline 15 June 2022.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-1010 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-1010), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.