CVE-2015-0311: Adobe Flash Player Remote Code Execution Vulnerability
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.
Other sources
Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Adobe Flash Playerfrom your environment.Disconnect Adobe Flash Player if it is still in use (product is end-of-life).
- Compensating control
Ensure systems running Adobe Flash Player (versions through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X; and 11.2.202.438 on Linux) are disconnected to prevent remote code execution.
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0311?
CVE-2015-0311 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2015-0311?
To fix CVE-2015-0311, update your Adobe Flash Player to version 16.0.0.288 or later.
Which products are affected by CVE-2015-0311?
Adobe Flash Player versions 11.2.202.438 and earlier, as well as versions 13.0.0.262, 14.x, 15.x, and 16.x up to 16.0.0.287 are affected.
Is there any known active exploitation of CVE-2015-0311?
Yes, CVE-2015-0311 was exploited in the wild close to its disclosure in January 2015.
What kind of attack vector is involved in CVE-2015-0311?
CVE-2015-0311 allows remote attackers to execute arbitrary code via unspecified vectors within Adobe Flash Player.