First published: Thu Jul 09 2015(Updated: )
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player for Internet Explorer 11 | <=11.2.202.468 | |
Linux Kernel | ||
Adobe Flash Player for Internet Explorer 11 | <=13.0.0.289 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.125 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.145 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.176 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.179 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.152 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.167 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.189 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.223 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.239 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.246 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.235 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.257 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.287 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.296 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.134 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.169 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.188 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.190 | |
Adobe Flash Player for Internet Explorer 11 | =18.0.0.160 | |
Adobe Flash Player for Internet Explorer 11 | =18.0.0.194 | |
macOS Yosemite | ||
Microsoft Windows | ||
Adobe AIR | <=18.0.0.144 | |
Adobe AIR SDK and Compiler | <=18.0.0.144 | |
Adobe AIR SDK & Compiler | <=18.0.0.144 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3114 has been rated as a critical severity vulnerability due to its ability to allow attackers to bypass access restrictions.
To fix CVE-2015-3114, update Adobe Flash Player to version 18.0.0.203 or later, or update Adobe AIR to version 18.0.0.180 or later.
Adobe Flash Player versions before 13.0.0.302 and 14.x through 18.x prior to 18.0.0.203 are affected by CVE-2015-3114.
CVE-2015-3114 can be exploited on Windows, OS X, and Linux systems using vulnerable versions of Adobe Flash Player and Adobe AIR.
CVE-2015-3114 can lead to unauthorized access and execution of malicious code on the affected system.