CVE-2015-0313

Confirmed PUBLISHED

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before...

Adobe · Flash Player
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical

At a Glance

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.

metasploit cisa windows linux
CVE Published
Feb 02, 2015
Exploitation Reported
Apr 13, 2022
CVSS
9.8 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • openSUSE-SU-2015:0238 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008...
  • openSUSE-SU-2015:0237 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007...
  • SUSE-SU-2015:0236 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006...
  • SUSE-SU-2015:0239 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009...
  • 62895 secunia.com · Third-Party Advisory http://secunia.com/advisories/62895
Show 11 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.