Skip to content
COOEY

EXPOSURES › CVE-2016-1010

CVE-2016-1010

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-1010 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

An integer overflow vulnerability in Adobe Flash Player and AIR allowed attackers to execute arbitrary code.

This integer overflow flaw in Adobe Flash Player and AIR enabled remote code execution, allowing attackers to compromise systems without user interaction. DIB organizations must ensure all legacy software like Flash is patched or disabled, as unpatched RCE vulnerabilities are high-priority compliance risks under NIST 800-171. The vulnerability was actively exploited in the wild, demonstrating the severe impact of neglecting known CVEs.

Shame score — Adobe failed to patch a known integer overflow vulnerability that enabled remote code execution, and the flaw was actively exploited in the wild, representing a negligent, avoidable failure with severe compliance and security consequences.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized