Junglewise Threat Intelligence

CVE-2015-7645: Adobe Flash Player Arbitrary Code Execution Vulnerability

CVE-2015-7645 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-03

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Flash Player is vulnerable to arbitrary code execution when processing a specially crafted SWF file. This vulnerability was actively exploited in the wild by the 'Pawn Storm' campaign prior to being patched.

Affected products

  • Adobe Flash Player 18.x through 18.0.0.252
  • Adobe Flash Player 19.x through 19.0.0.207
  • Adobe Flash Player 11.x through 11.2.202.535 (Linux)

Timeline

  • 2015-10-13: disclosed: Exploited in the wild in October 2015 according to NVD description and Trend Micro report.
  • 2015-10-14: exploited: Reported as used in Pawn Storm campaign.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats