CVE-2015-3043
KEVmassMemory Corruption RCE in Adobe Flash Player
CISA: Adobe Flash Player Memory Corruption Vulnerability
CVE-2015-3043 is an out-of-bounds write (memory corruption) flaw in Adobe Flash Player that is triggered when the player processes specially crafted Flash content, such as a malicious SWF file delivered through a web browser or an embedded application. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Flash, typically the logged-on desktop user. Any system running Adobe Flash Player, across browsers and operating systems at the time of disclosure, was affected; CISA notes the product is now end-of-life and should be disconnected if still in use. The vulnerability is known to be exploited in the wild: CISA added it to the KEV catalog on 2022-03-03, EPSS assigns it a 73.9% probability of exploitation within 30 days (99th percentile), and public reporting associates the technique with APT28 operations.
What to do: No further patch will be issued since Flash Player is end-of-life: locate and fully uninstall Flash from systems in your inventory, and block or remove SWF content in legacy internal applications. Check for browsers or business applications that still load Flash via bundled or embedded runtimes and disable that functionality. Given its KEV listing, prioritize complete removal over compensating controls.
| Adobe Flash Player | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.
- Affected
- Adobe Flash Player
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- Adobe
- Products
- Flash Player
- Weakness
- CWE-787