CVE-2015-7645: Adobe Flash Player Arbitrary Code Execution Vulnerability
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.
Other sources
Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If any affected Adobe Flash Player versions (18.x through 18.0.0.252, 19.x through 19.0.0.207 on Windows and OS X; 11.x through 11.2.202.535 on Linux) are still in use, disconnect them from the network because the impacted product is end-of-life.
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7645?
CVE-2015-7645 is considered a critical vulnerability that allows remote attackers to execute arbitrary code through a crafted SWF file.
How do I fix CVE-2015-7645?
To fix CVE-2015-7645, ensure that you update Adobe Flash Player to the latest version provided by Adobe.
What versions of Adobe Flash Player are affected by CVE-2015-7645?
CVE-2015-7645 affects Adobe Flash Player versions 18.x prior to 18.0.0.252 and 19.x prior to 19.0.0.207.
How can CVE-2015-7645 be exploited?
CVE-2015-7645 can be exploited by attackers through a crafted SWF file, which may lead to arbitrary code execution on the victim's machine.
Is there a workaround for CVE-2015-7645?
As a temporary workaround for CVE-2015-7645, users can disable Adobe Flash Player in their browsers or uninstall it until an update is applied.