← Vulnerability feed

Vulnerability record · CVE-2016-1019 · published 7 April 2016

CVE-2016-1019: Adobe Flash Player memory corruption allows code execution

Adobe · Flash Player Desktop Runtime

Adobe Flash Player 21.0.0.197 and earlier contains an unspecified memory corruption flaw that can crash the application or allow arbitrary code execution. Adobe confirmed it was exploited in the wild in April 2016, making it a real-world attack vector rather than a theoretical bug. The record gives no root-cause detail (CWE is 'noinfo'), so the exact vulnerable code path is unknown.

9.8 CVSS 3.1 Critical CISA KEV since 3 Mar 2022 Known ransomware use EPSS 22% · top 2.4%
9.8CVSS 3.1 base score, v2 10.0
22%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
5Affected product versions listed by NVD
32References
14 Aug 2026Last modified by NVD

Description

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, confirmed in-the-wild exploitation, KEV listing with ransomware association, and an end-of-life product that cannot be patched make this a top remediation priority.

What it is

Adobe Flash Player 21.0.0.197 and earlier contains an unspecified memory corruption flaw that can crash the application or allow arbitrary code execution. Adobe confirmed it was exploited in the wild in April 2016, making it a real-world attack vector rather than a theoretical bug. The record gives no root-cause detail (CWE is 'noinfo'), so the exact vulnerable code path is unknown.

Impact

An attacker can crash the Flash process or execute arbitrary code in its context, which typically means code execution with the privileges of the user running the browser or Flash runtime. Successful exploitation can lead to full host compromise and, per CISA, has been associated with ransomware campaigns.

Attack surface

Reachable remotely over the network with no authentication and no user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N), though in practice delivery is via a malicious or compromised web page or embedded Flash content. Any host still running Flash Player 21.0.0.197 or earlier is exposed.

Exploitation

Adobe stated it was exploited in the wild in April 2016, and CISA added it to KEV on 2022-03-03 with known ransomware campaign use. EPSS is 0.22487 (97.6th percentile), indicating elevated predicted exploitation activity.

What to do

  • Patch or remove Flash Player immediately; Adobe Flash Player is end-of-life, so uninstall it rather than relying on updates.
  • Follow CISA KEV guidance: disconnect end-of-life Flash-bearing systems if they cannot be removed or isolated.
  • Apply the Microsoft MS16-050 update for the bundled Flash component on affected Windows systems.
  • Block Flash content in browsers and disable the plugin enterprise-wide via policy.
  • Restrict outbound browsing and email attachments on systems that cannot drop Flash, and segment them from critical assets.

Detection

  • Hunt for Flash Player versions 21.0.0.197 or earlier across endpoints and browsers.
  • Monitor for Flash process crashes (flash player plugin/browser child processes) followed by suspicious child process creation.
  • Alert on network fetches of .swf content from untrusted or newly registered domains.
  • Review endpoint telemetry for code execution originating from browser or Flash plugin processes, especially on hosts with known ransomware precursor activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-1019 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Adobe Flash Player Arbitrary Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 24 March 2022.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blogs.adobe.com/psirt/?p=1330 Broken LinkVendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00009.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00010.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00012.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00055.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.html Broken Link
http://rhn.redhat.com/errata/RHSA-2016-0610.html Third Party Advisory
http://www.securityfocus.com/bid/85856 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1035491 Broken LinkThird Party AdvisoryVDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-050 PatchThird Party AdvisoryVendor Advisory
https://helpx.adobe.com/security/products/flash-player/apsa16-01.html Vendor Advisory
https://helpx.adobe.com/security/products/flash-player/apsb16-10.html Vendor Advisory
https://security.gentoo.org/glsa/201606-08 Third Party Advisory
https://www.fireeye.com/blog/threat-research/2016/04/cve-2016-1019_a_new.html Broken Link
http://blogs.adobe.com/psirt/?p=1330 Broken LinkVendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00009.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00010.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00012.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00055.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.html Broken Link
http://rhn.redhat.com/errata/RHSA-2016-0610.html Third Party Advisory
http://www.securityfocus.com/bid/85856 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1035491 Broken LinkThird Party AdvisoryVDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-050 PatchThird Party AdvisoryVendor Advisory
https://helpx.adobe.com/security/products/flash-player/apsa16-01.html Vendor Advisory
https://helpx.adobe.com/security/products/flash-player/apsb16-10.html Vendor Advisory
https://security.gentoo.org/glsa/201606-08 Third Party Advisory
https://www.fireeye.com/blog/threat-research/2016/04/cve-2016-1019_a_new.html Broken Link
https://github.com/cisagov/vulnrichment/issues/196 Issue Tracking
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-1019 US Government Resource

Track CVE-2016-1019 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed9.8CVE-2015-5122Adobe Flash Player ActionScript 3 Use-After-Free in DisplayObjectA use-after-free flaw in the DisplayObject class of Adobe Flash Player's ActionScript 3 implementation is triggered by crafted Flash content that mis…KEVEPSS 94%analysed9.8CVE-2015-5119Adobe Flash Player ActionScript 3 ByteArray use-after-freeA use-after-free flaw exists in the ByteArray class of the ActionScript 3 implementation in Adobe Flash Player. Crafted Flash content that overrides …KEVEPSS 99%analysed9.8CVE-2015-3113Adobe Flash Player heap buffer overflow allows remote code executionAdobe Flash Player contains a heap-based buffer overflow (CWE-122/CWE-787) reachable through unspecified vectors. It affects Flash Player before 13.0…KEVEPSS 100%analysed9.8CVE-2015-3043Adobe Flash Player memory corruption allows arbitrary code executionAdobe Flash Player contains an out-of-bounds write (CWE-787) that corrupts memory and can lead to arbitrary code execution or a denial of service. Th…KEVEPSS 74%analysed9.8CVE-2015-0313Adobe Flash Player use-after-free allows remote code executionAdobe Flash Player contains a use-after-free (CWE-416) flaw reachable through unspecified vectors. It affects Flash Player before 13.0.0.269 and 14.x…KEVEPSS 95%analysed

Source: NIST National Vulnerability Database (record CVE-2016-1019), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.