Junglewise Threat Intelligence

CVE-2015-3113: Adobe Flash Player Heap-Based Buffer Overflow Vulnerability

CVE-2015-3113 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-04-13

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

A heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code via unspecified vectors. The vulnerability was actively exploited in the wild starting in June 2015.

Affected products

  • Adobe Systems Incorporated Flash Player before 13.0.0.296, 14.x through 18.x before 18.0.0.194 on Windows and OS X, and before 11.2.202.468 on Linux

Timeline

  • 2015-06: exploited: Exploited in the wild in June 2015.
  • 2022-04-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats