CVE-2015-3102: Infoleak
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow remote attackers to bypass the Same Origin Policy via unspecified vectors, a different vulnerability than CVE-2015-3098 and CVE-2015-3099.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3102?
CVE-2015-3102 has a critical severity rating due to potential exploitability by unauthorized attackers.
How do I fix CVE-2015-3102?
To fix CVE-2015-3102, update Adobe Flash Player and Adobe AIR to the latest versions provided by Adobe.
Which software versions are affected by CVE-2015-3102?
CVE-2015-3102 affects Adobe Flash Player versions before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, as well as several versions of Adobe AIR.
Can CVE-2015-3102 be exploited remotely?
Yes, CVE-2015-3102 can be exploited remotely through malicious Flash content.
Is there a workaround for CVE-2015-3102 if I cannot update?
Currently, the best workaround for CVE-2015-3102 is to disable Flash Player or use alternative media solutions.