EXPOSURES › CVE-2016-1010
CVE-2016-1010
HIGH ⌖ ON CISA KEV · EXPLOITEDAn integer overflow vulnerability in Adobe Flash Player and AIR allowed attackers to execute arbitrary code.
This integer overflow flaw in Adobe Flash Player and AIR enabled remote code execution, allowing attackers to compromise systems without user interaction. DIB organizations must ensure all legacy software like Flash is patched or disabled, as unpatched RCE vulnerabilities are high-priority compliance risks under NIST 800-171. The vulnerability was actively exploited in the wild, demonstrating the severe impact of neglecting known CVEs.
Shame score — Adobe failed to patch a known integer overflow vulnerability that enabled remote code execution, and the flaw was actively exploited in the wild, representing a negligent, avoidable failure with severe compliance and security consequences.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |