cbcvebase.
CVE-2015-3042
published 2015-04-14

CVE-2015-3042: Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute…

PriorityP268critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
36.81%
98.3th percentile
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3043.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
adobeflash_player< 11.2.202.45711.2.202.457
adobeflash_player< 13.0.0.28113.0.0.281
adobeflash_player<= 11.2.202.451
adobeflash_player<= 13.0.0.264
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player>= 14.0.0.125 < 17.0.0.16917.0.0.169
novellsuse_linux_enterprise_desktop
novellsuse_linux_enterprise_desktop
novellsuse_linux_enterprise_workstation_extension
opensuseevergreen
opensuseopensuse

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/37839.zip
  • Detect Flash content containing the degenerate PCRE conditional assertion pattern `(?(?)?)` or structurally equivalent zero-length assertion expressions that produce OP_BRAZERO before OP_CBRA in compiled PCRE bytecode, which causes an out-of-bounds ecode pointer jump.
  • Look for PCRE bytecode sequences containing opcode 0x66 (OP_BRAZERO / decimal 102) immediately preceding opcode 0x5e (OP_CBRA / decimal 94) inside Flash SWF content, as this is the compiled form of the malicious regex.
  • Monitor for exploitation of CVE-2015-3043 (memory corruption via PCRE zero-length assertion) in Adobe Flash Player versions before 13.0.0.281 (Windows/OS X) and before 11.2.202.457 (Linux); this CVE was actively exploited in the wild in April 2015.
  • The out-of-bounds condition manifests as an ecode pointer jumping far outside the allocated heap buffer (e.g., from 0x600e0000dfe7 to 0x600e00013dea); heap-spray or large unexpected ecode delta in PCRE match execution within Flash processes is a strong indicator.
  • ·The NVD source references CVE-2015-3043 (not CVE-2015-3042); the exploit-db entry covers the PCRE zero-length assertion bug which is listed as a distinct vulnerability from CVE-2015-3042 in the NVD advisory. Confirm the correct CVE mapping before operationalizing these indicators.
  • ·The PoC crash was demonstrated specifically against Chrome/Flash on x64 Linux; exploitation reliability and bytecode offsets may differ on Windows/OS X Flash builds.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.