CVE-2015-0313
CRITICAL KEVAdobe Flash Player < 11.2.202.442 - Use After Free
Title source: ruleDescription
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
Exploits (4)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/36579
exploitdb
WORKING POC
by SecurityObscurity · textremotewindows
https://www.exploit-db.com/exploits/36491
nomisec
WRITEUP
21 stars
by SecurityObscurity · poc
https://github.com/SecurityObscurity/cve-2015-0313
metasploit
WORKING POC
GREAT
by Unknown, hdarwin, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/adobe_flash_worker_byte_array_uaf.rb
References (18)
Scores
CVSS v3
9.8
EPSS
0.9254
EPSS Percentile
99.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-04-13
VulnCheck KEV
2015-01-14
InTheWild.io
2015-01-14
ENISA EUVD
EUVD-2015-0326
CWE
CWE-416
Status
published
Products (10)
adobe/flash_player
< 11.2.202.442
microsoft/edge
microsoft/internet_explorer
10
microsoft/internet_explorer
11
opensuse/evergreen
11.4
opensuse/opensuse
13.1
opensuse/opensuse
13.2
suse/linux_enterprise_desktop
11 sp3
suse/linux_enterprise_desktop
12
suse/linux_enterprise_workstation_extension
12
Published
Feb 02, 2015
KEV Added
Apr 13, 2022
Tracked Since
Feb 18, 2026