CVE-2015-0318
Adobe Flash Player < 13.0.0.269 and 14.x-16.x < 16.0.0.305 - Remote Code Execution
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2015-0318.
PoCs published by Metasploit, Mark Brand, sinn3r, including Metasploit module exploits/windows/browser/adobe_flash_pcre.
AI-analyzed exploit summary This Metasploit module exploits CVE-2015-0318, a vulnerability in Adobe Flash Player's PCRE engine, allowing arbitrary execution of PCRE bytecode via a malformed regex pattern. It delivers a malicious SWF file to trigger the vulnerability and execute a PowerShell payload.
Description
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0314, CVE-2015-0316, CVE-2015-0321, CVE-2015-0329, and CVE-2015-0330.
Exploits (2)
This Metasploit module exploits CVE-2015-0318, a vulnerability in Adobe Flash Player's PCRE engine, allowing arbitrary execution of PCRE bytecode via a malformed regex pattern. It delivers a malicious SWF file to trigger the vulnerability and execute a PowerShell payload.
This Metasploit module exploits a PCRE regex vulnerability in Adobe Flash Player (CVE-2015-0318) by leveraging a compilation logic error in handling the \c escape sequence followed by multi-byte UTF8 characters, allowing arbitrary PCRE bytecode execution. It delivers a malicious SWF file to trigger the vulnerability and achieve remote code execution.