CVE-2015-4428: Use After Free
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3118, CVE-2015-3124, CVE-2015-3127, CVE-2015-3128, CVE-2015-3129, CVE-2015-3131, CVE-2015-3132, CVE-2015-3136, CVE-2015-3137, CVE-2015-4430, and CVE-2015-5117.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4428?
The severity of CVE-2015-4428 is considered critical due to its potential to allow arbitrary code execution.
How do I fix CVE-2015-4428?
To fix CVE-2015-4428, upgrade Adobe Flash Player to the latest version available beyond 13.0.0.302, 14.x through 18.x before 18.0.0.203, or Adobe AIR to version 18.0.0.180 or newer.
Which versions of Adobe Flash Player are affected by CVE-2015-4428?
Adobe Flash Player versions before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 are affected by CVE-2015-4428.
What platforms are impacted by CVE-2015-4428?
CVE-2015-4428 affects Adobe Flash Player on Windows, OS X, and Linux as well as Adobe AIR on various platforms.
Is Adobe AIR impacted by CVE-2015-4428?
Yes, Adobe AIR versions before 18.0.0.180 are also affected by CVE-2015-4428.