CVE-2015-5119: Adobe Flash Player Use-After-Free Vulnerability
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.
Other sources
A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If Adobe Flash Player is still in use (impacted EOL product), disconnect it from the network to mitigate the use-after-free (ByteArray/ActionScript 3) remote code execution risk.
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5119?
CVE-2015-5119 has a critical severity rating as it allows remote attackers to execute arbitrary code.
How do I fix CVE-2015-5119?
To fix CVE-2015-5119, upgrade Adobe Flash Player to a version that is 13.0.0.297 or later, or 18.0.0.195 or later.
Which versions of Adobe Flash Player are affected by CVE-2015-5119?
Adobe Flash Player versions from 13.x up to and including 13.0.0.296 and 14.x up to and including 18.0.0.194 are affected by CVE-2015-5119.
Can CVE-2015-5119 affect users on macOS?
Yes, CVE-2015-5119 affects users on macOS using the vulnerable versions of Adobe Flash Player.
Is Linux vulnerable to CVE-2015-5119?
Yes, some versions of Adobe Flash Player on Linux are vulnerable to CVE-2015-5119, specifically those up to and including version 11.2.202.468.