peter bassill · operator
$ cve CVE-2015-7645 JSON

CVE-2015-7645 KEV EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 65.3% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-24.

Description

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS65.34% — more likely to be exploited than 99% of all CVEs
On CISA KEVyes — remediate by 2022-03-24
Public exploityes
Published2015-10-15
Last modified2026-06-17

CISA KEV

NameAdobe Flash Player Arbitrary Code Execution Vulnerability
Added2022-03-03
Due2022-03-24
Vendor / productAdobe / Flash Player
Ransomware useknown

Affected (13)

VendorProduct
adobeflash player
applemac os x
linuxlinux kernel
microsoftwindows
opensuseevergreen
opensuseopensuse
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server from rhui
redhatenterprise linux workstation
suselinux enterprise desktop
suselinux enterprise workstation extension

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD