Executive brief
Adobe Flash Player is vulnerable to arbitrary code execution when processing a specially crafted SWF file. This vulnerability was actively exploited in the wild by the 'Pawn Storm' campaign prior to being patched.
Affected products
- Adobe Flash Player 18.x through 18.0.0.252
- Adobe Flash Player 19.x through 19.0.0.207
- Adobe Flash Player 11.x through 11.2.202.535 (Linux)
Timeline
- 2015-10-13: disclosed: Exploited in the wild in October 2015 according to NVD description and Trend Micro report.
- 2015-10-14: exploited: Reported as used in Pawn Storm campaign.
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.