CVE-2015-5123
KEVmassUse-After-Free RCE in Adobe Flash Player (AS3 BitmapData)
CISA: Adobe Flash Player Use-After-Free Vulnerability
CVE-2015-5123 is a use-after-free memory corruption flaw (CWE-416) in the BitmapData class of the ActionScript 3 (AS3) implementation of Adobe Flash Player. It is triggered remotely when Flash processes specially crafted ActionScript 3 content, such as a malicious SWF file, that frees a BitmapData object while it is still in use, corrupting memory. A successful attacker can execute arbitrary code in the context of the Flash runtime or crash it, causing a denial of service. Any system running affected builds of Flash Player is exposed, including desktop browsers, embedded or legacy applications, and industrial systems still relying on the now end-of-life plugin. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-04-13, confirming in-the-wild exploitation; EPSS assigns an 18.5% probability of exploitation within 30 days (97th percentile), and no public proof-of-concept exploit is cataloged.
What to do: Per CISA's required action, disconnect or fully remove/disable Adobe Flash Player wherever it is still installed, since the product is end-of-life. If Flash is still required for legacy web apps or OT/HMI systems, apply the Adobe security bulletin that fixes this CVE (APSB15-18, released July 2015) or later, and isolate the host from untrusted web and email content. As part of KEV remediation, hunt for Flash process crashes, unexpected SWF content in traffic, and child processes spawned by Flash.
| Adobe Flash Player | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
- Affected
- Adobe Flash Player
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- Adobe
- Products
- Flash Player
- Weakness
- CWE-416