First published: Fri Aug 14 2015(Updated: )
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5127, CVE-2015-5130, CVE-2015-5134, CVE-2015-5540, CVE-2015-5550, CVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5559, CVE-2015-5561, CVE-2015-5563, CVE-2015-5564, and CVE-2015-5565.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player for Internet Explorer 11 | <=18.0.0.209 | |
macOS Yosemite | ||
Microsoft Windows | ||
Adobe Flash Player for Internet Explorer 11 | <=11.2.202.491 | |
Linux Kernel | ||
Adobe AIR | <=18.0.0.180 | |
Adobe AIR SDK and Compiler | <=18.0.0.180 | |
Adobe AIR SDK & Compiler | <=18.0.0.180 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5539 is classified as critical due to its potential to allow attackers to execute arbitrary code.
To fix CVE-2015-5539, update Adobe Flash Player to version 18.0.0.232 or later, or Adobe AIR to version 18.0.0.199 or later.
Adobe Flash Player versions before 18.0.0.232 on Windows and OS X, and versions before 11.2.202.508 on Linux are affected.
CVE-2015-5539 may allow attackers to execute arbitrary code through unspecified vectors, leading to potential system compromise.
CVE-2015-5539 is primarily a remote vulnerability that can be exploited over a network.