High severity7.3NVD Advisory· Published Apr 9, 2016· Updated May 6, 2026
CVE-2016-1014
CVE-2016-1014
Description
Untrusted search path vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows local users to gain privileges via a Trojan horse resource in an unspecified directory.
Affected products
9- cpe:2.3:a:adobe:air_desktop_runtime:*:*:*:*:*:*:*:*Range: <=21.0.0.176
- cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*Range: <=21.0.0.176
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=11.2.202.577
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:*range: <=21.0.0.197
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:*range: <=21.0.0.197
- cpe:2.3:a:adobe:flash_player:*:*:*:*:esr:*:*:*range: <=18.0.0.333
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:*range: <=21.0.0.197
- cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:*Range: <=21.0.0.197
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-050nvdPatchThird Party Advisory
- helpx.adobe.com/security/products/flash-player/apsb16-10.htmlnvdPatchVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.htmlnvdBroken LinkThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.htmlnvdBroken LinkThird Party Advisory
- packetstormsecurity.com/files/137532/Adobe-Flash-Player-DLL-Hijacking.htmlnvdThird Party AdvisoryVDB Entry
- rhn.redhat.com/errata/RHSA-2016-0610.htmlnvdThird Party Advisory
- seclists.org/fulldisclosure/2016/Jun/39nvdMailing ListThird Party Advisory
- www.securityfocus.com/archive/1/538699/100/0/threadednvdBroken LinkThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1035509nvdBroken LinkThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.