SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-8453

Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers…

MEDIUM 4.3EPSS 4.98%

Does this matter?

Lower severity and a low EPSS score (4.98%). Track it; it rarely justifies an emergency change on its own.

Description

Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to bypass the ASLR protection mechanism via JIT data, a different vulnerability than CVE-2015-8409 and CVE-2015-8440.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
4.98% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
adobe/flash player · adobe/air · adobe/air sdk · adobe/air sdk \& compiler
Source
psirt@adobe.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.