Junglewise Threat Intelligence

CVE-2015-5123: Adobe Flash Player Use-After-Free Vulnerability

CVE-2015-5123 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-04-13

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

A use-after-free vulnerability exists in the BitmapData class within the ActionScript 3 (AS3) implementation of Adobe Flash Player. Remote attackers can exploit this by using crafted Flash content that overrides the valueOf function, leading to arbitrary code execution or denial of service.

Affected products

  • Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations

Timeline

  • 2015-07: exploited: Exploited in the wild as a zero-day following the Hacking Team leak.
  • 2022-04-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats