ZeroHour

CVE-2015-0310

KEVmass

ASLR Protection-Mechanism Bypass in Adobe Flash Player

CISA: Adobe Flash Player ASLR Bypass Vulnerability

CVSS
EPSS
15%p97
Published
KEV added
AI analysis

CVE-2015-0310 is a protection-mechanism weakness in Adobe Flash Player in which the player fails to properly restrict the discovery of memory addresses, allowing an attacker to defeat Address Space Layout Randomization (ASLR), the mitigation that randomizes where code and data are loaded in memory. It is triggered by running attacker-controlled Flash (SWF) content in a browser, ActiveX control, or embedded player, typically as part of an exploit chain in which the attacker infers module addresses during a heap spray. The flaw grants no code execution by itself; its value to attackers is that it makes memory-corruption exploits deterministic and reliable, and it is generally chained with another Flash vulnerability to achieve remote code execution. Any system still running Adobe Flash Player is affected, a product now end-of-life, so exposure is concentrated in legacy enterprise web applications, kiosks, embedded players, and browser/OS builds that shipped with Flash bundled. CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2022-05-25, confirming exploitation in the wild; no public proof-of-concept is known, no CVSS score has been published, and EPSS estimates a 15.2% chance of exploitation within 30 days (97th percentile).

What to do: Per CISA's required action, treat Flash as retired: inventory all systems for Flash usage (browser plugins, IE/ActiveX controls, standalone players, and embedded enterprise applications) and remove or disconnect it where found. Where Flash must remain, ensure the latest available Adobe release is installed and restrict execution to trusted SWF content, prioritizing internet-facing endpoints given the KEV listing.

Affected
Adobe Flash Player
Estimated exposure
mass~1M-10M+ endpoints still running Flash in legacy enterprise apps, kiosks, or bundled-browser contexts — Basis: Flash Player was effectively ubiquitous on desktops for two decades and was bundled with Windows and every major browser, so even after end-of-life a residual base of at least one million legacy endpoints is plausible; no current…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Flash Player
Weakness
CWE-264

In the news