SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2015-0310

Adobe Flash Player ASLR Bypass Vulnerability

KEVHIGH 7.8EPSS 15.2%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
15.22% probability · 97th percentile
CISA KEV
Listed 25 May 2022 · due 15 June 2022
Weakness
CWE-200
Affected
adobe/flash player
Source
psirt@adobe.com

CISA notes

The impacted product is end-of-life and should be disconnected if still in use. https://nvd.nist.gov/vuln/detail/CVE-2015-0310

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.