CVE-2015-0311
KEVmassUse-After-Free Remote Code Execution in Adobe Flash Player
CISA: Adobe Flash Player Remote Code Execution Vulnerability
CVE-2015-0311 is a use-after-free memory corruption flaw in Adobe Flash Player that Adobe patched in an emergency January 2015 release (APSB15-02); CISA catalogs it generically as an unspecified remote code execution vulnerability. It is triggered when a victim's Flash plugin processes maliciously crafted SWF content, typically embedded in a web page or delivered via malvertising and exploit kits such as Angler, and requires no authentication. A successful attacker gains arbitrary code execution in the context of the logged-in user, enabling malware installation; contemporaneous 2015 reporting tied Flash 0-day malvertising campaigns (e.g., Fessleak) to ransomware such as TeslaCrypt. Anyone running an affected Flash Player version in a browser or standalone install was exposed, but Flash Player has been end-of-life since the end of 2020, so the exposed population today consists of legacy, unmaintained systems. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-04-13 and carries an EPSS of 85.8% (100th percentile), although no public proof-of-concept is tracked.
What to do: Upgrade to the patched release from Adobe's January 2015 advisory — 16.0.0.296 (with 13.0.0.262 for the extended-support 13.x branch) — or, preferably, remove Flash entirely since it reached end-of-life on December 31, 2020; CISA's required action is to disconnect or retire any systems still running it. Check browsers, embedded devices, and internal applications for residual Flash plugins, and disable Flash or block SWF content as a mitigation where the plugin cannot be removed.
| Adobe Flash Player | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.
- Affected
- Adobe Flash Player
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- Adobe
- Products
- Flash Player