Executive brief
A heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code via unspecified vectors. The vulnerability was actively exploited in the wild starting in June 2015.
Affected products
- Adobe Systems Incorporated Flash Player before 13.0.0.296, 14.x through 18.x before 18.0.0.194 on Windows and OS X, and before 11.2.202.468 on Linux
Timeline
- 2015-06: exploited: Exploited in the wild in June 2015.
- 2022-04-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.