CVE-2015-3106: Use After Free
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3103 and CVE-2015-3107.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3106?
CVE-2015-3106 is rated as a high severity vulnerability due to its use-after-free nature, which can lead to arbitrary code execution.
How do I fix CVE-2015-3106?
To fix CVE-2015-3106, update Adobe Flash Player and Adobe AIR to versions 13.0.0.292 or later for Flash and 18.0.0.144 or later for AIR.
Which versions of Adobe products are affected by CVE-2015-3106?
CVE-2015-3106 affects Adobe Flash Player versions earlier than 13.0.0.292 and versions 14.x through 18.x before 18.0.0.160, as well as Adobe AIR versions prior to 18.0.0.144.
What platforms are impacted by CVE-2015-3106?
CVE-2015-3106 impacts Adobe Flash Player and Adobe AIR on Windows, macOS, and Linux platforms.
Is there a workaround for CVE-2015-3106 until I can update?
Currently, no official workarounds are provided for CVE-2015-3106, so the best mitigation is to apply the latest updates.