CVE-2015-0310
Adobe Flash Player ASLR Bypass Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 15.22% probability · 97th percentile
- CISA KEV
- Listed 25 May 2022 · due 15 June 2022
- Weakness
- CWE-200
- Affected
- adobe/flash player
- Source
- psirt@adobe.com
CISA notes
The impacted product is end-of-life and should be disconnected if still in use. https://nvd.nist.gov/vuln/detail/CVE-2015-0310
References
- http://helpx.adobe.com/security/products/flash-player/apsb15-02.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/62452Broken Link
- http://secunia.com/advisories/62601Broken Link
- http://secunia.com/advisories/62660Broken Link
- http://secunia.com/advisories/62740Broken Link
- http://security.gentoo.org/glsa/glsa-201502-02.xmlThird Party Advisory
- http://www.securityfocus.com/bid/72261Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1031609Broken Link, Third Party Advisory, VDB Entry
- http://helpx.adobe.com/security/products/flash-player/apsb15-02.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/62452Broken Link
- http://secunia.com/advisories/62601Broken Link
- http://secunia.com/advisories/62660Broken Link
- http://secunia.com/advisories/62740Broken Link
- http://security.gentoo.org/glsa/glsa-201502-02.xmlThird Party Advisory
- http://www.securityfocus.com/bid/72261Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1031609Broken Link, Third Party Advisory, VDB Entry
- https://github.com/cisagov/vulnrichment/issues/196Issue Tracking
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-0310US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.