ZeroHour

CVE-2015-3113

KEVmass

Heap-Based Buffer Overflow RCE in Adobe Flash Player

CISA: Adobe Flash Player Heap-Based Buffer Overflow Vulnerability

CVSS
EPSS
100%p100
Published
KEV added
AI analysis

CVE-2015-3113 is a heap-based buffer overflow (CWE-119) in Adobe Flash Player that is triggered when Flash processes specially crafted SWF content, for example when a browser, ad, or Flash-embedded application renders an attacker-supplied page or file. A successful exploit allows a remote, unauthenticated attacker to execute arbitrary code in the context of the current user. Anyone still running Adobe Flash Player is affected; the product reached end-of-life on December 31, 2020, and CISA's required action is to disconnect or stop using it if it is still deployed. The flaw was exploited in the wild as a zero-day in targeted attacks in June 2015 (fixed by Adobe's emergency update APSB15-11) and was added to the CISA KEV catalog on April 13, 2022; EPSS currently assigns a 99.9% probability of exploitation within 30 days.

What to do: Uninstall Adobe Flash Player from all systems, since it has been end-of-life since December 31, 2020 and CISA's required action is to disconnect or stop using anything that still depends on it. If Flash must remain (e.g., legacy admin consoles or kiosks), ensure it runs at least the June 2015 emergency fix (APSB15-11) and ideally the final pre-EOL build 32.0.0.465, and eliminate any browser-facing Flash surface that renders untrusted SWF content. Audit enterprise environments for embedded Flash runtimes and migrate those applications to HTML5 or other supported runtimes.

Affected
Adobe Flash PlayerNo specific version range given in the CISA data; historically, all Flash Player versions prior to Adobe's June 2015 emergency security update (APSB15-11)
Estimated exposure
masstens of millions of legacy desktops worldwide still carried Flash at end-of-life (Flash historically ran on ~90% of desktops); residual active installs… — Flash was preinstalled on the vast majority of PCs for two decades, and even after end-of-life removal is incomplete because legacy enterprise apps, kiosks, and old browsers still embed the Flash runtime, so the affected base almost…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Flash Player
Weakness
CWE-119

In the news