ZeroHour

CVE-2015-5123

KEVmass

Use-After-Free RCE in Adobe Flash Player (AS3 BitmapData)

CISA: Adobe Flash Player Use-After-Free Vulnerability

CVSS
EPSS
18%p97
Published
KEV added
AI analysis

CVE-2015-5123 is a use-after-free memory corruption flaw (CWE-416) in the BitmapData class of the ActionScript 3 (AS3) implementation of Adobe Flash Player. It is triggered remotely when Flash processes specially crafted ActionScript 3 content, such as a malicious SWF file, that frees a BitmapData object while it is still in use, corrupting memory. A successful attacker can execute arbitrary code in the context of the Flash runtime or crash it, causing a denial of service. Any system running affected builds of Flash Player is exposed, including desktop browsers, embedded or legacy applications, and industrial systems still relying on the now end-of-life plugin. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-04-13, confirming in-the-wild exploitation; EPSS assigns an 18.5% probability of exploitation within 30 days (97th percentile), and no public proof-of-concept exploit is cataloged.

What to do: Per CISA's required action, disconnect or fully remove/disable Adobe Flash Player wherever it is still installed, since the product is end-of-life. If Flash is still required for legacy web apps or OT/HMI systems, apply the Adobe security bulletin that fixes this CVE (APSB15-18, released July 2015) or later, and isolate the host from untrusted web and email content. As part of KEV remediation, hunt for Flash process crashes, unexpected SWF content in traffic, and child processes spawned by Flash.

Affected
Adobe Flash Player
Estimated exposure
massLikely hundreds of thousands to millions of residual installs worldwide (Flash historically ran on well over a billion devices) — Adobe Flash was once near-universally deployed across desktop browsers and web applications, and it persists in legacy enterprise web apps, IE-based intranet tools, industrial/HMI systems, and regional distributions such as China's…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Flash Player
Weakness
CWE-416

In the news