CVE-2015-3113
KEVmassHeap-Based Buffer Overflow RCE in Adobe Flash Player
CISA: Adobe Flash Player Heap-Based Buffer Overflow Vulnerability
CVE-2015-3113 is a heap-based buffer overflow (CWE-119) in Adobe Flash Player that is triggered when Flash processes specially crafted SWF content, for example when a browser, ad, or Flash-embedded application renders an attacker-supplied page or file. A successful exploit allows a remote, unauthenticated attacker to execute arbitrary code in the context of the current user. Anyone still running Adobe Flash Player is affected; the product reached end-of-life on December 31, 2020, and CISA's required action is to disconnect or stop using it if it is still deployed. The flaw was exploited in the wild as a zero-day in targeted attacks in June 2015 (fixed by Adobe's emergency update APSB15-11) and was added to the CISA KEV catalog on April 13, 2022; EPSS currently assigns a 99.9% probability of exploitation within 30 days.
What to do: Uninstall Adobe Flash Player from all systems, since it has been end-of-life since December 31, 2020 and CISA's required action is to disconnect or stop using anything that still depends on it. If Flash must remain (e.g., legacy admin consoles or kiosks), ensure it runs at least the June 2015 emergency fix (APSB15-11) and ideally the final pre-EOL build 32.0.0.465, and eliminate any browser-facing Flash surface that renders untrusted SWF content. Audit enterprise environments for embedded Flash runtimes and migrate those applications to HTML5 or other supported runtimes.
| Adobe Flash Player | No specific version range given in the CISA data; historically, all Flash Player versions prior to Adobe's June 2015 emergency security update (APSB15-11) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.
- Affected
- Adobe Flash Player
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- Adobe
- Products
- Flash Player
- Weakness
- CWE-119