Executive brief
A use-after-free vulnerability exists in the DisplayObject class within the ActionScript 3 (AS3) implementation of Adobe Flash Player. Remote attackers can exploit this by leveraging improper handling of the opaqueBackground property via crafted Flash content to execute arbitrary code or cause a denial of service.
Affected products
- Adobe Systems Incorporated Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations
Timeline
- 2015-07: exploited: Exploited in the wild in July 2015.
- 2022-04-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.