CVE-2015-3043: Adobe Flash Player Memory Corruption Vulnerability
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.
Other sources
A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Flash Playerto a version that resolves this vulnerability.Fixed in 13.0.0.281 - Upgrade
Upgrade
Adobe Flash Player 14.xto a version that resolves this vulnerability.Fixed in 17.0.0.169 - Upgrade
Upgrade
Adobe Flash Player 11.2.202.457to a version that resolves this vulnerability.Fixed in 11.2.202.457 - Compensating control
Because the impacted Adobe Flash Player product is end-of-life, disconnect it from networks if it is still in use.
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3043?
CVE-2015-3043 has a high severity rating as it allows attackers to execute arbitrary code or cause denial of service due to memory corruption.
How do I fix CVE-2015-3043?
To fix CVE-2015-3043, update Adobe Flash Player to version 17.0.0.169 or later.
Which versions of Adobe Flash Player are affected by CVE-2015-3043?
CVE-2015-3043 affects Adobe Flash Player versions prior to 13.0.0.281, 14.x through 17.x before 17.0.0.169, and 11.2.202.457 on Linux.
Can CVE-2015-3043 affect Linux systems running Adobe Flash Player?
Yes, CVE-2015-3043 affects Linux systems running Adobe Flash Player versions earlier than 11.2.202.457.
Is there a workaround for CVE-2015-3043 if I can't update Adobe Flash Player?
While the best approach is to update to the latest version, temporary mitigation includes disabling Flash Player in your browser or application until updated.