CVE-2015-0318

Adobe Flash Player < 13.0.0.269 and 14.x-16.x < 16.0.0.305 - Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2015-0318. PoCs published by Metasploit, Mark Brand, sinn3r, including Metasploit module exploits/windows/browser/adobe_flash_pcre.

AI-analyzed exploit summary This Metasploit module exploits CVE-2015-0318, a vulnerability in Adobe Flash Player's PCRE engine, allowing arbitrary execution of PCRE bytecode via a malformed regex pattern. It delivers a malicious SWF file to trigger the vulnerability and execute a PowerShell payload.

Description

Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0314, CVE-2015-0316, CVE-2015-0321, CVE-2015-0329, and CVE-2015-0330.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/36420

This Metasploit module exploits CVE-2015-0318, a vulnerability in Adobe Flash Player's PCRE engine, allowing arbitrary execution of PCRE bytecode via a malformed regex pattern. It delivers a malicious SWF file to trigger the vulnerability and execute a PowerShell payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Adobe Flash Player 16.0.0.235
No auth needed
Prerequisites: Target must visit a malicious webpage · Adobe Flash Player 16.0.0.235 must be installed · Internet Explorer must be used
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Mark Brand, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/adobe_flash_pcre.rb

This Metasploit module exploits a PCRE regex vulnerability in Adobe Flash Player (CVE-2015-0318) by leveraging a compilation logic error in handling the \c escape sequence followed by multi-byte UTF8 characters, allowing arbitrary PCRE bytecode execution. It delivers a malicious SWF file to trigger the vulnerability and achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Adobe Flash Player 16.0.0.235
No auth needed
Prerequisites: Target must be using Internet Explorer on Windows 7 with Adobe Flash Player 16.0.0.235 installed
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (14)

Core 14
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201502-02.xml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62895
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62886
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62777
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72514
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0140.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031706
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/100702
Vendor Advisory x_refsource_confirm
https://technet.microsoft.com/library/security/2755801

Scores

EPSS 0.7578
EPSS Percentile 99.5%

Details

Status published
Products (15)
adobe/flash_player 14.0.0.125
adobe/flash_player 14.0.0.145
adobe/flash_player 14.0.0.176
adobe/flash_player 14.0.0.179
adobe/flash_player 15.0.0.152
adobe/flash_player 15.0.0.167
adobe/flash_player 15.0.0.189
adobe/flash_player 15.0.0.223
adobe/flash_player 15.0.0.239
adobe/flash_player 15.0.0.246
... and 5 more
Published Feb 06, 2015
Tracked Since Feb 18, 2026