CVE-2015-0313

CRITICAL KEV

Adobe Flash Player < 11.2.202.442 - Use After Free

Title source: rule

Description

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/36579
exploitdb WORKING POC
by SecurityObscurity · textremotewindows
https://www.exploit-db.com/exploits/36491
nomisec WRITEUP 21 stars
by SecurityObscurity · poc
https://github.com/SecurityObscurity/cve-2015-0313
metasploit WORKING POC GREAT
by Unknown, hdarwin, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/adobe_flash_worker_byte_array_uaf.rb

References (18)

Scores

CVSS v3 9.8
EPSS 0.9254
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-04-13
VulnCheck KEV 2015-01-14
InTheWild.io 2015-01-14
ENISA EUVD EUVD-2015-0326
CWE
CWE-416
Status published
Products (10)
adobe/flash_player < 11.2.202.442
microsoft/edge
microsoft/internet_explorer 10
microsoft/internet_explorer 11
opensuse/evergreen 11.4
opensuse/opensuse 13.1
opensuse/opensuse 13.2
suse/linux_enterprise_desktop 11 sp3
suse/linux_enterprise_desktop 12
suse/linux_enterprise_workstation_extension 12
Published Feb 02, 2015
KEV Added Apr 13, 2022
Tracked Since Feb 18, 2026