CVE-2016-1014
Untrusted search path vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows local users to gain privileges via a Trojan horse resource in an unspecified directory.
Date published : 2016-04-08
http://www.securityfocus.com/archive/1/538699/100/0/threaded
https://helpx.adobe.com/security/products/flash-player/apsb16-10.html