CVE-2015-0313 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 95.3% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-04.
Description
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 95.27% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-416 |
| On CISA KEV | yes — remediate by 2022-05-04 |
| Public exploit | yes |
| Published | 2015-02-02 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Adobe Flash Player Use-After-Free Vulnerability |
|---|---|
| Added | 2022-04-13 |
| Due | 2022-05-04 |
| Vendor / product | Adobe / Flash Player |
| Ransomware use | none reported |
Affected (16)
| Vendor | Product |
|---|---|
| adobe | flash player |
| apple | mac os x |
| linux | linux kernel |
| microsoft | edge |
| microsoft | internet explorer |
| microsoft | windows |
| microsoft | windows 10 1507 |
| microsoft | windows 8 |
| microsoft | windows 8.1 |
| microsoft | windows rt |
| microsoft | windows rt 8.1 |
| microsoft | windows server 2012 |
| opensuse | evergreen |
| opensuse | opensuse |
| suse | linux enterprise desktop |
| suse | linux enterprise workstation extension |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Adobe Flash Player - ByteArray With Workers Use-After-Free (Metasploit) | 2015-03-31 |
| exploit-db | Adobe Flash Player - Arbitrary Code Execution | 2015-03-25 |
References
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.html
- http://packetstormsecurity.com/files/131189/Adobe-Flash-Player-ByteArray-With-Workers-Use-After-Free.html
- http://secunia.com/advisories/62528
- http://secunia.com/advisories/62777
- http://secunia.com/advisories/62895
- http://www.osvdb.org/117853
- http://www.securityfocus.com/bid/72429
- http://www.securitytracker.com/id/1031686
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100641
- https://helpx.adobe.com/security/products/flash-player/apsa15-02.html
- https://helpx.adobe.com/security/products/flash-player/apsb15-04.html
- https://technet.microsoft.com/library/security/2755801
- https://www.exploit-db.com/exploits/36579/
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.html
→ the Explorer · watch your stack · NVD