Skip to main content

CVE detail

CVE-2016-1019

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

CVSS 9.8 · CriticalBuzz score 71.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 71.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
28 evidence mentions in the snapshot
Diversity score
16.0
6 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
28 source links · newest first
  • The APT28 group is trying to exploit the CVE-2017-11292 Flash zero-day before users receive patches or update their systems. Security experts at Proofpoint collected evidence of several malware campaigns, powered by the Russian APT28 group, that rely on a Flash zero-day vulnerability that Adobe patched earlier this week. According to the experts who observed attacks on organizations […]

    newssecurityaffairs.comOct 22, 2017, 11:29 AM
  • A new exploit kit (EK) has emerged recently on underground forums, where a malware developer is advertising it starting at just $80.

    newswww.securityweek.comAug 15, 2017, 12:46 PM
  • The Disdain exploit kit is available for rent on a daily, weekly, or monthly basis for prices of $80, $500, and $1,400 respectively. The security researcher David Montenegro discovered a new exploit kit dubbed Disdain that is offered for rent on underground hacking forums by a malware developer using the pseudonym of Cehceny. https://twitter.com/CryptoInsane/status/895151680861253632 The Disdain exploit […]

    newssecurityaffairs.comAug 15, 2017, 7:48 AM
  • The Stegano exploit kit, also known as Astrum, continues to evolve, recently its authors adopted the Diffie-Hellman algorithm to hinder analysis. The Stegano exploit kit made was associated in the past with a massive AdGholas malvertising campaign that delivered malware, mostly Gozi and RAMNIT trojans. Experts at TrendMicro also observed the exploit kit in the Seamless malvertising campaign. “Astrum’s […]

    newssecurityaffairs.comMay 20, 2017, 7:31 PM
  • After receiving multiple updates, the Stegano exploit kit (EK) recently adopted the Diffie-Hellman algorithm to hinder analysis, Trend Micro security researchers warn.

    newswww.securityweek.comMay 19, 2017, 11:59 AM
  • Exploit kits: Winter 2017 reviewMalwarebytes Labs

    A few months have passed since our Fall 2016 review of the most common exploit kits we are seeing in our telemetry and honeypots. Today, we take another look at the current (bleak) EK scene by going over RIG, Sundown, Neutrino and Magnitude. There haven’t been any major changes in the past little while and exploit kit-related infections remain low compared to those via malicious spam. This is in part due to the lack of fresh and reliable exploits in today’s drive-by landscape. Pseudo-Darkleech and EITest are the most popular redirection campaigns from compromised websites. They refer to code that is injected into – for the most part – WordPress , Joomla , or Drupal websites and automatically redirects visitors to an exploit kit landing page. Malvertising campaigns keep fuelling redirections to exploit kits as well, but can greatly vary in size and impact. The daily malverts from shady ad networks continue unchanged while the larger attacks going after top ad networks and publishers co…

    newswww.malwarebytes.comMar 8, 2017, 5:00 PM
  • It’s a new year and while some things change, some things stay the same (or similar). There’s lots of FUD about the sophisticated cyber attacks that are multi-threaded and obfuscated. Certainly there are attacks that fall into this category, but if you look at all of the cybercrime activity from the past year, it’s clear that the majority of threats do not have the level of sophistication that is often talked about.

    newswww.securityweek.comJan 20, 2017, 4:16 PM
  • Based on an analysis in 2015 of over 100 exploit kits (EKs) and known vulnerabilities, Adobe Flash was the unfortunate winner of the most frequently exploited product. Now that it’s 2017, companies are joking that maybe it’s time to give Flash the old heave ho’ to retirement. While Adobe has worked tirelessly to make Flash more […]

    newswww.csoonline.comJan 17, 2017, 7:00 PM
  • Experts from Heimdal Security warned of a spike in cyber attacks leveraging the popular RIG Exploit kit to deliver the Cerber Ransomware. The RIG exploit kit is even more popular in the criminal ecosystem, a few days ago security experts at Heimdal Security warned of a spike in cyber attacks leveraging the popular Neutrino and […]

    newssecurityaffairs.comJan 16, 2017, 6:44 AM
  • A newly observed campaign leveraging the RIG exploit kit is targeting outdated versions of popular applications such as Flash, Internet Explorer, or Microsoft Edge to distribute the Cerber ransomware, Heimdal Security warns.

    newswww.securityweek.comJan 15, 2017, 6:55 PM
  • Experts from the firm Recorded Future published a report on the most common vulnerabilities used by threat actors in the exploit kits. Recorded Future published an interesting report on the most common vulnerabilities used by threat actors in the exploit kits. The experts observed that Adobe Flash Player and Microsoft products (Internet Explorer, Silverlight, Windows) continue […]

    newssecurityaffairs.comDec 6, 2016, 8:18 PM
  • The most common vulnerabilities used by exploit kits in the past year affect Flash Player, Windows, Internet Explorer and Silverlight, according to a report published on Tuesday by threat intelligence firm Recorded Future.

    newswww.securityweek.comDec 6, 2016, 3:28 PM
  • Exploit kits: Fall 2016 reviewMalwarebytes Labs

    There have been interesting developments with exploit kits in the past few months to say the least, with the disappearance of…

    newswww.malwarebytes.comNov 8, 2016, 5:00 PM
  • Unit 42 has reported on various Sofacy group attacks over the last year, most recently with a post on Komplex, an OS X variant of a tool commonly used by the Sofacy group. In the same timeframe of the Komplex attacks, we collected several weaponized documents that use a tactic previously not observed in use

    vendorunit42.paloaltonetworks.comOct 17, 2016, 8:00 PM
  • Operators behind the Neutrino EK have added the code to exploit an Internet Explorer flaw that was recently patched with the release of the MS16-053. Operators behind the infamous Neutrino EK have recently added the code to exploit an Internet Explorer vulnerability that was patched with the release of the MS16-053 security bulletin. The MS16-053 bulletin patched […]

    newssecurityaffairs.comJul 15, 2016, 1:20 PM
  • The developers of the Neutrino exploit kit have added a recently patched Internet Explorer vulnerability to their arsenal after researchers published a proof-of-concept (PoC) exploit.

    newswww.securityweek.comJul 15, 2016, 7:44 AM
  • The authors of the Magnitude exploit kit are integrating the exploit code for the CVE-2016-411 Adobe Flash Player vulnerability. Recently security experts from FireEye detailed the exploit chain for the Adobe Flaw Vulnerability CVE-2016-4117 that was first spotted by the company earlier May. The CVE-2016-4117 flaw affects older versions of the Adobe Flash, after the disclosure of […]

    newssecurityaffairs.comMay 23, 2016, 10:22 AM
  • On Tuesday, Adobe has pushed out security updates for Cold Fusion and Adobe Acrobat and Reader, but has also announced an update for Flash Player that should be released on Thursday and will fix a zero-day flaw (CVE-2016-4117) that’s being actively exploited in attacks in the wild. What kind of attacks? Adobe didn’t say. But the vulnerability is considered to be critical, as successful exploitation could cause a crash and potentially allow an attacker to … More →

    newswww.helpnetsecurity.comMay 11, 2016, 2:59 PM
  • Researchers at Cisco have spotted an instance of the Nuclear exploit kit where the final payload is downloaded via the Tor network in order to make tracking more difficult.

    newswww.securityweek.comApr 11, 2016, 9:11 AM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs The website of the Hungarian Government temporarily shut by cyberattack CloudFlare considers 94 percent of the Tor traffic as per se malicious Security Affairs newsletter Round 54 – News of the week Hacking connected lightbulbs to breach […]

    newssecurityaffairs.comApr 10, 2016, 10:01 AM
  • Adobe Systems released a security update for Flash Player to fix 24 critical vulnerabilities, including one that hackers have been exploiting to infect computers with ransomware over the past week. The company advised users Thursday to upgrade to the newly released Flash Player 21.0.0.213 on Windows and Mac and Flash Player 11.2.202.616 on Linux. The […]

    newswww.csoonline.comApr 8, 2016, 11:49 AM
  • Cyber criminals are exploiting the Flash player zero-day vulnerability (CVE-2016-1019) affecting Flash Player 21.0.0.197 and earlier disclosed by Adobe. Cyber criminals are already exploiting the Flash player zero-day vulnerability (CVE-2016-1019) affecting Flash Player 21.0.0.197 and earlier (CVE-2016-1019) disclosed by Adobe this week. Researchers at security firm Proofpoint confirmed that cyber gangs are exploiting it to distribute a ransomware dubbed Cerber. […]

    newssecurityaffairs.comApr 8, 2016, 8:59 AM
  • Adobe released a Flash Player update on Thursday to patch a zero-day vulnerability that has been leveraged by cybercriminals to deliver malware via the Magnitude exploit kit.

    newswww.securityweek.comApr 7, 2016, 9:02 PM
  • The latest zero-day vulnerability in Adobe Systems’ Flash player has been used over the last few days to distribute ransomware called Cerber, email security vendor Proofpoint said. Adobe said it would patch the flaw, CVE-2016-1019, on Thursday. The vulnerability affects all versions of Flash Player on Windows, Mac, Linux and Chrome OS. Ryan Kalember, senior vice […]

    newswww.csoonline.comApr 7, 2016, 7:54 PM
  • Botched Flash 0day Gets PatchedMalwarebytes Labs

    Adobe has just released a patch for the infamous Flash Player to fix a vulnerability actively exploited in the wild by some…

    newswww.malwarebytes.comApr 7, 2016, 5:00 PM
  • Adobe is working on an emergency patch for its Flash Player after attackers are reportedly exploiting a critical flaw. The vulnerability, CVE-2016-1019, affects Flash Player version 21.0.0.197 on Windows, Mac, Linux and Chrome OS, according to an advisory published on Tuesday. The flaw is being actively exploited on Windows XP and 7 systems running Flash Player […]

    newswww.csoonline.comApr 6, 2016, 12:38 PM
  • A new Flash Player zero-day vulnerability (CVE-2016-1019) has been actively exploited by threat actors in attacks against systems running Windows XP and 7. Once again a zero-day vulnerability in the Adobe Flash Player 21.0.0.197 is threatening Internet users worldwide. The news was spread by Adobe that issued a security alert on Tuesday anticipating an imminent […]

    newssecurityaffairs.comApr 6, 2016, 9:52 AM
  • Adobe informed users on Tuesday that it’s preparing a patch for a Flash Player zero-day vulnerability that has been actively exploited by malicious actors.

    newswww.securityweek.comApr 6, 2016, 7:45 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence