First published: Thu Oct 15 2015(Updated: )
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | ||
All of | ||
Any of | ||
Adobe Acrobat Reader | >=18.0.0.160<=18.0.0.252 | |
Adobe Acrobat Reader | =19.0.0.185 | |
Adobe Acrobat Reader | =19.0.0.207 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows | ||
All of | ||
Adobe Acrobat Reader | <=11.2.202.535 | |
Linux Kernel | ||
openSUSE Evergreen | =11.4 | |
openSUSE | =13.1 | |
openSUSE | =13.2 | |
SUSE Linux Enterprise Desktop with Beagle | =11-sp3 | |
SUSE Linux Enterprise Desktop with Beagle | =11-sp4 | |
SUSE Linux Enterprise Desktop with Beagle | =12 | |
SUSE Linux Enterprise Workstation Extension | =12 | |
redhat enterprise Linux desktop | =5.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux eus | =6.7 | |
redhat enterprise Linux server | =5.0 | |
redhat enterprise Linux server | =6.0 | |
Red Hat Enterprise Linux Server Supplementary EUS | =5.0 | |
Red Hat Enterprise Linux Server Supplementary EUS | =6.0 | |
redhat enterprise Linux workstation | =5.0 | |
redhat enterprise Linux workstation | =6.0 | |
Adobe Acrobat Reader | <=19.0.0.207 | |
Apple iOS and macOS | ||
Microsoft Windows | ||
Adobe Acrobat Reader | <=11.2.202.535 | |
Linux Kernel | ||
All of | ||
Any of | ||
>=18.0.0.160<=18.0.0.252 | ||
=19.0.0.185 | ||
=19.0.0.207 | ||
Any of | ||
All of | ||
<=11.2.202.535 | ||
=11.4 | ||
=13.1 | ||
=13.2 | ||
=11-sp3 | ||
=11-sp4 | ||
=12 | ||
=12 | ||
=5.0 | ||
=6.0 | ||
=6.7 | ||
=5.0 | ||
=6.0 | ||
=5.0 | ||
=6.0 | ||
=5.0 | ||
=6.0 |
The impacted product is end-of-life and should be disconnected if still in use.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7645 is considered a critical vulnerability that allows remote attackers to execute arbitrary code through a crafted SWF file.
To fix CVE-2015-7645, ensure that you update Adobe Flash Player to the latest version provided by Adobe.
CVE-2015-7645 affects Adobe Flash Player versions 18.x prior to 18.0.0.252 and 19.x prior to 19.0.0.207.
CVE-2015-7645 can be exploited by attackers through a crafted SWF file, which may lead to arbitrary code execution on the victim's machine.
As a temporary workaround for CVE-2015-7645, users can disable Adobe Flash Player in their browsers or uninstall it until an update is applied.