CVE-2015-3132: Use After Free
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3118, CVE-2015-3124, CVE-2015-3127, CVE-2015-3128, CVE-2015-3129, CVE-2015-3131, CVE-2015-3136, CVE-2015-3137, CVE-2015-4428, CVE-2015-4430, and CVE-2015-5117.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3132?
CVE-2015-3132 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2015-3132?
To fix CVE-2015-3132, update Adobe Flash Player to the latest version that is not affected, specifically versions 13.0.0.302 or higher, and for Adobe AIR, update to version 18.0.0.180 or higher.
Who is affected by CVE-2015-3132?
CVE-2015-3132 affects users of Adobe Flash Player versions prior to 13.0.0.302 and 14.x to 18.x before 18.0.0.203, along with older versions of Adobe AIR.
What can attackers do with CVE-2015-3132?
Attackers can exploit CVE-2015-3132 to execute arbitrary code on the affected systems, which may lead to full system compromise.
What platforms are vulnerable to CVE-2015-3132?
CVE-2015-3132 affects Adobe Flash Player on Windows, OS X, and Linux as well as Adobe AIR on all major platforms.