CVE-2015-0310
KEVmassASLR Protection-Mechanism Bypass in Adobe Flash Player
CISA: Adobe Flash Player ASLR Bypass Vulnerability
CVE-2015-0310 is a protection-mechanism weakness in Adobe Flash Player in which the player fails to properly restrict the discovery of memory addresses, allowing an attacker to defeat Address Space Layout Randomization (ASLR), the mitigation that randomizes where code and data are loaded in memory. It is triggered by running attacker-controlled Flash (SWF) content in a browser, ActiveX control, or embedded player, typically as part of an exploit chain in which the attacker infers module addresses during a heap spray. The flaw grants no code execution by itself; its value to attackers is that it makes memory-corruption exploits deterministic and reliable, and it is generally chained with another Flash vulnerability to achieve remote code execution. Any system still running Adobe Flash Player is affected, a product now end-of-life, so exposure is concentrated in legacy enterprise web applications, kiosks, embedded players, and browser/OS builds that shipped with Flash bundled. CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2022-05-25, confirming exploitation in the wild; no public proof-of-concept is known, no CVSS score has been published, and EPSS estimates a 15.2% chance of exploitation within 30 days (97th percentile).
What to do: Per CISA's required action, treat Flash as retired: inventory all systems for Flash usage (browser plugins, IE/ActiveX controls, standalone players, and embedded enterprise applications) and remove or disconnect it where found. Where Flash must remain, ensure the latest available Adobe release is installed and restrict execution to trusted SWF content, prioritizing internet-facing endpoints given the KEV listing.
| Adobe Flash Player | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.
- Affected
- Adobe Flash Player
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- Adobe
- Products
- Flash Player
- Weakness
- CWE-264