CVE-2015-7645

HIGH KEV RANSOMWARE

Adobe Flash Player <18.0.0.252-19.0.0.207 & 11.2.202.535 - RCE

Title source: llm

Description

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/38490

References (15)

Scores

CVSS v3 7.8
EPSS 0.8453
EPSS Percentile 99.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-03-03
VulnCheck KEV 2015-10-13
InTheWild.io 2015-10-13
ENISA EUVD EUVD-2015-7548
Ransomware Use Confirmed
Status published
Products (18)
adobe/flash_player 19.0.0.185
adobe/flash_player 19.0.0.207
adobe/flash_player 18.0.0.160 - 18.0.0.252
opensuse/evergreen 11.4
opensuse/opensuse 13.1
opensuse/opensuse 13.2
redhat/enterprise_linux_desktop 5.0
redhat/enterprise_linux_desktop 6.0
redhat/enterprise_linux_eus 6.7
redhat/enterprise_linux_server 5.0
... and 8 more
Published Oct 15, 2015
KEV Added Mar 03, 2022
Tracked Since Feb 18, 2026