Junglewise Threat Intelligence

CVE-2015-5119: Adobe Flash Player Use-After-Free Vulnerability

CVE-2015-5119 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-03

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

A use-after-free vulnerability exists in the ByteArray class within the ActionScript 3 implementation of Adobe Flash Player. Remote attackers can exploit this by using crafted Flash content that overrides the valueOf function, leading to arbitrary code execution or denial of service.

Affected products

  • Adobe Flash Player 13.x through 13.0.0.296 (Windows/OS X)
  • Adobe Flash Player 14.x through 18.0.0.194 (Windows/OS X)
  • Adobe Flash Player 11.x through 11.2.202.468 (Linux)

Timeline

  • 2015-07: exploited: Exploited in the wild as part of the Hacking Team leak.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats