CVE-2015-0310: Adobe Flash Player ASLR Bypass Vulnerability
Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.
Other sources
Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If Adobe Flash Player is still in use, disconnect it from the network (since the impacted product is end-of-life).
- Compensating control
Disconnect the impacted Flash Player installs on Windows, OS X, and Linux if still in use, as the end-of-life product should be disconnected.
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0310?
CVE-2015-0310 is rated as critical due to its potential to allow attackers to bypass ASLR protections.
How do I fix CVE-2015-0310?
To fix CVE-2015-0310, upgrade Adobe Flash Player to a version that is not affected by the vulnerability.
What versions are affected by CVE-2015-0310?
CVE-2015-0310 affects Adobe Flash Player versions prior to 13.0.0.262, 14.x through 16.x before 16.0.0.287 on Windows and OS X, and before 11.2.202.438 on Linux.
Can CVE-2015-0310 be exploited remotely?
Yes, CVE-2015-0310 can be exploited remotely by attackers to execute arbitrary code.
What products are impacted by CVE-2015-0310?
CVE-2015-0310 impacts Adobe Flash Player for Internet Explorer 11 across multiple operating systems including Windows and OS X.