CVE-2015-0313: Adobe Flash Player Use-After-Free Vulnerability
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
Other sources
Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Flash Playerto a version that resolves this vulnerability.Fixed in 13.0.0.269 - Upgrade
Upgrade
Adobe Flash Playerto a version that resolves this vulnerability.Fixed in 16.0.0.305 - Upgrade
Upgrade
Adobe Flash Playerto a version that resolves this vulnerability.Fixed in 11.2.202.442 - Compensating control
Disconnect Adobe Flash Player from the network if it is still in use, since the impacted product is end-of-life.
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0313?
CVE-2015-0313 has a severity rating of critical as it allows remote attackers to execute arbitrary code.
How do I fix CVE-2015-0313?
To fix CVE-2015-0313, update Adobe Flash Player to version 13.0.0.269 or later, or version 16.0.0.305 or later.
Which Adobe Flash Player versions are affected by CVE-2015-0313?
Adobe Flash Player versions prior to 13.0.0.269 and between 14.x and 16.x before 16.0.0.305 are affected by CVE-2015-0313.
Can I still use Adobe Flash Player if I upgrade to a version after CVE-2015-0313?
Yes, upgrading to a secure version will protect against CVE-2015-0313 vulnerabilities while allowing the use of Adobe Flash Player.
Is there a known exploitation of CVE-2015-0313?
Yes, CVE-2015-0313 was actively exploited in the wild as of February 2015.