Junglewise Threat Intelligence

CVE-2015-0310: Adobe Flash Player ASLR Bypass Vulnerability

CVE-2015-0310 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-05-25

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Flash Player fails to properly restrict the discovery of memory addresses, allowing attackers to bypass Address Space Layout Randomization (ASLR). This vulnerability was exploited in the wild to facilitate further exploitation on Windows and other platforms.

Affected products

  • Adobe Systems Incorporated Flash Player before 13.0.0.262, 14.x through 16.x before 16.0.0.287 on Windows and OS X; before 11.2.202.438 on Linux

Timeline

  • 2015-01: exploited: Exploited in the wild in January 2015.
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats