ZeroHour

CVE-2015-3043

KEVmass

Memory Corruption RCE in Adobe Flash Player

CISA: Adobe Flash Player Memory Corruption Vulnerability

CVSS
EPSS
74%p99
Published
KEV added
AI analysis

CVE-2015-3043 is an out-of-bounds write (memory corruption) flaw in Adobe Flash Player that is triggered when the player processes specially crafted Flash content, such as a malicious SWF file delivered through a web browser or an embedded application. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Flash, typically the logged-on desktop user. Any system running Adobe Flash Player, across browsers and operating systems at the time of disclosure, was affected; CISA notes the product is now end-of-life and should be disconnected if still in use. The vulnerability is known to be exploited in the wild: CISA added it to the KEV catalog on 2022-03-03, EPSS assigns it a 73.9% probability of exploitation within 30 days (99th percentile), and public reporting associates the technique with APT28 operations.

What to do: No further patch will be issued since Flash Player is end-of-life: locate and fully uninstall Flash from systems in your inventory, and block or remove SWF content in legacy internal applications. Check for browsers or business applications that still load Flash via bundled or embedded runtimes and disable that functionality. Given its KEV listing, prioritize complete removal over compensating controls.

Affected
Adobe Flash Player
Estimated exposure
mass≈1 billion+ devices at the time of disclosure (Flash ran on ~99% of internet-connected PCs in 2015); far fewer end-of-life installs remain today — Flash Player was historically installed on roughly 99% of internet-connected desktops (on the order of a billion installs) at the time of the 2015 disclosure, while the residual end-of-life installed base is now much smaller but…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Flash Player
Weakness
CWE-787

In the news