ZeroHour

CVE-2015-0311

KEVmass

Use-After-Free Remote Code Execution in Adobe Flash Player

CISA: Adobe Flash Player Remote Code Execution Vulnerability

CVSS
EPSS
86%p100
Published
KEV added
AI analysis

CVE-2015-0311 is a use-after-free memory corruption flaw in Adobe Flash Player that Adobe patched in an emergency January 2015 release (APSB15-02); CISA catalogs it generically as an unspecified remote code execution vulnerability. It is triggered when a victim's Flash plugin processes maliciously crafted SWF content, typically embedded in a web page or delivered via malvertising and exploit kits such as Angler, and requires no authentication. A successful attacker gains arbitrary code execution in the context of the logged-in user, enabling malware installation; contemporaneous 2015 reporting tied Flash 0-day malvertising campaigns (e.g., Fessleak) to ransomware such as TeslaCrypt. Anyone running an affected Flash Player version in a browser or standalone install was exposed, but Flash Player has been end-of-life since the end of 2020, so the exposed population today consists of legacy, unmaintained systems. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-04-13 and carries an EPSS of 85.8% (100th percentile), although no public proof-of-concept is tracked.

What to do: Upgrade to the patched release from Adobe's January 2015 advisory — 16.0.0.296 (with 13.0.0.262 for the extended-support 13.x branch) — or, preferably, remove Flash entirely since it reached end-of-life on December 31, 2020; CISA's required action is to disconnect or retire any systems still running it. Check browsers, embedded devices, and internal applications for residual Flash plugins, and disable Flash or block SWF content as a mitigation where the plugin cannot be removed.

Affected
Adobe Flash Player
Estimated exposure
mass≈1 billion+ installs at the time of disclosure (near-universal desktop browser plugin); now limited to unmaintained EOL systems — Flash Player shipped on essentially every internet-connected desktop in 2015 (commonly cited near-99% reach), and CISA's note that the product is end-of-life means current exposure is residual legacy installs.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Flash Player

In the news