CVE-2015-5122: Adobe Flash Player Use-After-Free Vulnerability
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.
Other sources
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disconnect Adobe Flash Player from any clients/users if it is still in use, since the affected Adobe Flash Player versions are end-of-life.
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5122?
CVE-2015-5122 is rated as a critical severity vulnerability due to its potential exploitability and impact.
How do I fix CVE-2015-5122?
To fix CVE-2015-5122, update Adobe Flash Player to the latest version available.
What is the exploit type of CVE-2015-5122?
CVE-2015-5122 is a use-after-free vulnerability affecting the DisplayObject class in Adobe Flash Player.
Which versions of Adobe Flash Player are affected by CVE-2015-5122?
CVE-2015-5122 affects Adobe Flash Player versions 13.x through 13.0.0.302, 14.x through 18.0.0.203, and 11.x through 11.2.202.481.
What platforms are impacted by CVE-2015-5122?
CVE-2015-5122 impacts Adobe Flash Player on Windows, OS X, and Linux platforms.