CVE-2015-5119

CRITICAL KEV RANSOMWARE

Adobe Flash Player ByteArray Use After Free

Title source: metasploit

Description

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

Exploits (7)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/37523
github STUB 31 stars
by OpenSISE · cpoc
https://github.com/OpenSISE/CVE_PoC_Collect/tree/master/RCE/flash/CVE-2015-5119
nomisec WRITEUP 13 stars
by CiscoCXSecurity · client-side
https://github.com/CiscoCXSecurity/CVE-2015-5119_walkthrough
nomisec WORKING POC 12 stars
by jvazquez-r7 · poc
https://github.com/jvazquez-r7/CVE-2015-5119
nomisec WORKING POC 3 stars
by dangokyo · poc
https://github.com/dangokyo/CVE-2015-5119
vulncheck_xdb WORKING POC
client-side
https://github.com/Xattam1/Adobe-Flash-Exploits_17-18
metasploit WORKING POC GREAT
by Unknown, juan vazquez, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/adobe_flash_hacking_team_uaf.rb

References (18)

Scores

CVSS v3 9.8
EPSS 0.9315
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-03-03
VulnCheck KEV 2015-07-05
InTheWild.io 2015-07-05
ENISA EUVD EUVD-2015-5134
Ransomware Use Confirmed
CWE
CWE-416
Status published
Products (17)
adobe/flash_player 13.0.0.182 - 13.0.0296
opensuse/evergreen 11.4
opensuse/opensuse 13.1
opensuse/opensuse 13.2
redhat/enterprise_linux_desktop 5.0
redhat/enterprise_linux_desktop 6.0
redhat/enterprise_linux_eus 6.6
redhat/enterprise_linux_server 5.0
redhat/enterprise_linux_server 6.0
redhat/enterprise_linux_server_aus 6.6
... and 7 more
Published Jul 08, 2015
KEV Added Mar 03, 2022
Tracked Since Feb 18, 2026