CVE-2015-8651: Adobe Flash Player Integer Overflow Vulnerability
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.
Other sources
Integer overflow in Adobe Flash Player allows attackers to execute code.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If Adobe Flash Player/AIR/AIR SDK (including AIR SDK & Compiler) is still in use, disconnect it from the network because the impacted product is end-of-life.
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8651?
CVE-2015-8651 is rated as critical due to its potential to allow remote code execution.
How do I fix CVE-2015-8651?
To mitigate CVE-2015-8651, update Adobe Flash Player to version 18.0.0.324 or later, or update Adobe AIR to at least version 20.0.0.233.
Which versions of Adobe Flash Player are affected by CVE-2015-8651?
Adobe Flash Player versions prior to 18.0.0.324, specifically 19.x and 20.x version before 20.0.0.267, are affected by CVE-2015-8651.
Is Adobe AIR affected by CVE-2015-8651?
Yes, Adobe AIR versions before 20.0.0.233 are vulnerable to CVE-2015-8651.
What platforms are impacted by CVE-2015-8651?
CVE-2015-8651 affects Adobe Flash Player on Windows, OS X, and Linux, as well as Adobe AIR across these platforms.