CVE-2015-5122

Confirmed PUBLISHED

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on...

Adobe · Flash Player
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical

At a Glance

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.

linux windows metasploit cisa
CVE Published
Jul 14, 2015
Exploitation Reported
Apr 13, 2022
CVSS
9.8 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • SUSE-SU-2015:1255 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00028...
  • HPSBMU03409 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=144050155601375&w=2
  • SUSE-SU-2015:1258 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00029...
  • GLSA-201508-01 security.gentoo.org · Vendor Advisory https://security.gentoo.org/glsa/201508-01
  • HPSBHF03509 h20564.www2.hp.com · Vendor Advisory https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docI...
Show 15 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.