CVE-2015-3113

Confirmed PUBLISHED

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before...

Adobe · Flash Player
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical

At a Glance

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.

cisa windows linux metasploit
CVE Published
Jun 23, 2015
Exploitation Reported
Apr 13, 2022
CVSS
9.8 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • HPSBMU03409 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=144050155601375&w=2
  • RHSA-2015:1184 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2015-1184.html
  • GLSA-201507-13 security.gentoo.org · Vendor Advisory https://security.gentoo.org/glsa/201507-13
  • openSUSE-SU-2015:1180 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00002...
  • SUSE-SU-2015:1136 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00020...
Show 8 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.