peter bassill · operator
$ cve CVE-2015-3043 JSON

CVE-2015-3043 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 73.9% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-24.

Description

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS73.86% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2022-03-24
Public exploityes
Published2015-04-14
Last modified2026-06-17

CISA KEV

NameAdobe Flash Player Memory Corruption Vulnerability
Added2022-03-03
Due2022-03-24
Vendor / productAdobe / Flash Player
Ransomware usenone reported

Affected (14)

VendorProduct
adobeflash player
applemac os x
linuxlinux kernel
microsoftwindows
novellsuse linux enterprise desktop
novellsuse linux enterprise workstation extension
opensuseevergreen
opensuseopensuse
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server from rhui
redhatenterprise linux workstation

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD