First published: Fri Aug 14 2015(Updated: )
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5127, CVE-2015-5130, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550, CVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5559, CVE-2015-5563, CVE-2015-5564, and CVE-2015-5565.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | <=18.0.0.209 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
Macromedia Flash Player | <=11.2.202.491 | |
Linux Kernel | ||
Adobe | <=18.0.0.180 | |
Adobe AIR | <=18.0.0.180 | |
Adobe AIR SDK & Compiler | <=18.0.0.180 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5561 is a critical severity vulnerability that allows attackers to execute arbitrary code.
To fix CVE-2015-5561, update Adobe Flash Player to version 18.0.0.232 or later.
CVE-2015-5561 affects Adobe Flash Player before version 18.0.0.232, Adobe AIR before version 18.0.0.199, and several versions of Adobe AIR SDK.
No, if you're using an affected version of Adobe Flash Player, you should update immediately to avoid potential exploitation.
CVE-2015-5561 impacts Adobe Flash Player on Windows, OS X, and Linux systems.