Junglewise Threat Intelligence

CVE-2015-0313: Adobe Flash Player Use-After-Free Vulnerability

CVE-2015-0313 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-04-13

Technologies: Adobe Systems Incorporated Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

A use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code via unspecified vectors. The vulnerability was actively exploited in the wild targeting Windows, OS X, and Linux users.

Affected products

  • Adobe Systems Incorporated Flash Player before 13.0.0.269
  • Adobe Systems Incorporated Flash Player 14.x through 16.x before 16.0.0.305
  • Adobe Systems Incorporated Flash Player before 11.2.202.442 (Linux)

Timeline

  • 2015-02: exploited: Exploited in the wild in February 2015.
  • 2022-04-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats