CVE-2015-7648

Adobe Flash Player <18.0.0.255,19.x<19.0.0.226 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-7648. PoCs published by Google Security Research.

AI-analyzed exploit summary This exploit leverages a type confusion vulnerability in Adobe Flash's ObjectEncoder.dynamicPropertyWriter during serialization. By overriding the dynamicPropertyWriter with a non-function value, an attacker can achieve arbitrary code execution. The PoC requires manual bytecode modification to trigger the vulnerability.

Description

Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-7647.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/38970

This exploit leverages a type confusion vulnerability in Adobe Flash's ObjectEncoder.dynamicPropertyWriter during serialization. By overriding the dynamicPropertyWriter with a non-function value, an attacker can achieve arbitrary code execution. The PoC requires manual bytecode modification to trigger the vulnerability.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Adobe Flash Player (versions affected by CVE-2015-7648)
No auth needed
Prerequisites: Victim must load a malicious SWF file · Manual modification of the SWF bytecode
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-1913.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-2024.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033850
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201511-02
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/38970/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/77116

Scores

EPSS 0.2953
EPSS Percentile 98.0%

Details

Status published
Products (1)
adobe/flash_player < 11.2.202.535
Published Oct 18, 2015
Tracked Since Feb 18, 2026