Junglewise Threat Intelligence

CVE-2015-3043: Adobe Flash Player Memory Corruption Vulnerability

CVE-2015-3043 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-03

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

A memory corruption vulnerability (out-of-bounds write) in Adobe Flash Player allows for remote code execution or denial of service via unspecified vectors. The vulnerability was actively exploited in the wild starting in April 2015.

Affected products

  • Adobe Flash Player before 13.0.0.281
  • Adobe Flash Player 14.x through 17.x before 17.0.0.169
  • Adobe Flash Player before 11.2.202.457 on Linux

Timeline

  • exploited: Exploited in the wild in April 2015.
  • disclosed: NVD publication date.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats