CVE-2015-5119

Confirmed PUBLISHED

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and...

Adobe · Flash Player
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical

At a Glance

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

windows cisa linux metasploit
CVE Published
Jul 08, 2015
Exploitation Reported
Mar 03, 2022
CVSS
9.8 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • openSUSE-SU-2015:1207 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00015...
  • SUSE-SU-2015:1211 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00017...
  • RHSA-2015:1214 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2015-1214.html
  • SUSE-SU-2015:1214 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00018...
  • GLSA-201507-13 security.gentoo.org · Vendor Advisory https://security.gentoo.org/glsa/201507-13
Show 11 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.