First published: Thu Oct 15 2015(Updated: )
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | ||
All of | ||
Any of | ||
Macromedia Flash Player | >=18.0.0.160<=18.0.0.252 | |
Macromedia Flash Player | =19.0.0.185 | |
Macromedia Flash Player | =19.0.0.207 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
All of | ||
Macromedia Flash Player | <=11.2.202.535 | |
Linux Kernel | ||
Evergreen ILS | =11.4 | |
openSUSE | =13.1 | |
openSUSE | =13.2 | |
SUSE Linux Enterprise Desktop | =11-sp3 | |
SUSE Linux Enterprise Desktop | =11-sp4 | |
SUSE Linux Enterprise Desktop | =12 | |
SUSE Linux Workstation Extension | =12 | |
Red Hat Enterprise Linux Desktop | =5.0 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server EUS | =6.7 | |
Red Hat Enterprise Linux Server | =5.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server Supplementary EUS | =5.0 | |
Red Hat Enterprise Linux Server Supplementary EUS | =6.0 | |
Red Hat Enterprise Linux Workstation | =5.0 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Macromedia Flash Player | <=19.0.0.207 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
Macromedia Flash Player | <=11.2.202.535 | |
Linux Kernel |
The impacted product is end-of-life and should be disconnected if still in use.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7645 is considered a critical vulnerability that allows remote attackers to execute arbitrary code through a crafted SWF file.
To fix CVE-2015-7645, ensure that you update Adobe Flash Player to the latest version provided by Adobe.
CVE-2015-7645 affects Adobe Flash Player versions 18.x prior to 18.0.0.252 and 19.x prior to 19.0.0.207.
CVE-2015-7645 can be exploited by attackers through a crafted SWF file, which may lead to arbitrary code execution on the victim's machine.
As a temporary workaround for CVE-2015-7645, users can disable Adobe Flash Player in their browsers or uninstall it until an update is applied.