ZeroHour

CVE-2015-5122

KEVmass

Use-After-Free RCE in Adobe Flash Player AS3 DisplayObject

CISA: Adobe Flash Player Use-After-Free Vulnerability

CVSS
EPSS
94%p100
Published
KEV added
AI analysis

CVE-2015-5122 is a use-after-free vulnerability (CWE-416) in the DisplayObject class of the ActionScript 3 implementation in Adobe Flash Player. It is triggered when the Flash runtime processes crafted AS3/SWF content, typically a malicious Flash file loaded from a web page or delivered via an exploit kit, causing freed memory to be reused and letting a remote attacker execute arbitrary code in the user's context or crash the player (denial of service). Any system or browser still running affected Flash Player builds is affected; because Flash has reached end-of-life and no longer receives updates, environments that still rely on it are the primary at-risk population. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-04-13, related reporting shows it used by exploit kits and in watering-hole attacks, and EPSS assigns a 93.7% probability of exploitation within 30 days.

What to do: Follow CISA's required action: uninstall or disconnect Adobe Flash Player wherever it is still in use, since the product is end-of-life and receives no further patches. Inventory browsers, legacy web applications, and bundled software for residual Flash plug-ins and SWF content, and disable Flash content loading where immediate removal is not possible. For systems that must keep running Flash, isolate them and block exposure to untrusted web content, as drive-by exploit kit delivery was the observed attack pattern.

Affected
Adobe Flash Player
Estimated exposure
mass~1 billion+ historical installs (Flash ran on most internet-connected PCs at the 2015 disclosure); current residual post-EOL base unknown — Estimated from Flash's near-universal browser plugin market share around the time of disclosure (Adobe cited more than 1 billion cumulative installs); the December 2020 end-of-life makes the remaining install base a small, poorly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Flash Player
Weakness
CWE-416

In the news