LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2016-0984: Adobe Flash Player and AIR Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2016-0984 to its Known Exploited Vulnerabilities catalog on May 25, 2022, with a federal patch deadline of Jun 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.

CVE-2016-0984 is a use-after-free vulnerability in Adobe Flash Player and Adobe AIR that can allow an attacker to execute code. Because these products reached end-of-life status, any remaining installations represent ongoing risk and should be treated as high priority for removal rather than continued operation.

IT and security teams still encountering Flash or AIR components in legacy applications, browsers, or kiosks need a clear plan to locate them, confirm exposure, and eliminate the attack surface. Specifics such as exact build numbers or exploitation details must be confirmed against the original vendor advisory.

How it works

The flaw belongs to the use-after-free class (CWE-416). In this pattern, the application frees a block of memory but later continues to reference it. An attacker who can influence the timing or content of that memory can cause the process to use attacker-controlled data, which in turn can lead to arbitrary code execution inside the Flash Player or AIR runtime.

Public detail on the precise trigger or required user interaction is limited; defenders should assume that malicious content (for example, a crafted SWF or AIR application) delivered through a browser or other host could exercise the condition. No ransomware campaigns are documented against this CVE, yet the ability to run code still makes the vulnerability useful for initial access or privilege escalation on systems that still load the affected components.

Am I affected? How to find it in your systems

Adobe Flash Player historically appeared as a browser plug-in and as a standalone projector; Adobe AIR was used to package desktop and mobile applications. Both products are end-of-life and no longer receive security updates. Inventory efforts should therefore focus on discovery and removal rather than version triage alone.

How to remediate

CISA guidance states that the impacted products are end-of-life and should be disconnected if still in use. The primary remediation is therefore complete removal or isolation of every Flash Player and AIR instance.

If you can't patch immediately

Because the products are end-of-life, traditional patching is unavailable. Compensating controls must therefore focus on containment and monitoring until the software can be eliminated.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to system compromise and subsequent data theft. If you suspect the vulnerability was leveraged in your environment, follow standard incident-response procedures: isolate affected hosts, preserve forensic evidence, and assess what credentials or data may have been accessible. As an additional check, you can run a free exposure scan of your email addresses against known breach data sets to determine whether associated accounts appear in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Flash Player and AIR
WeaknessCWE-416
Added to CISA KEVMay 25, 2022
Federal patch deadlineJun 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities