cbcvebase.
CVE-2015-3043
published 2015-04-14

CVE-2015-3043: Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute…

PriorityP194critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
79.83%
99.6th percentile
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
adobeflash_player< 11.2.202.45711.2.202.457
adobeflash_player< 13.0.0.28113.0.0.281
adobeflash_player<= 11.2.202.451
adobeflash_player<= 13.0.0.264
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player>= 14.0.0.125 < 17.0.0.16917.0.0.169
novellsuse_linux_enterprise_desktop
novellsuse_linux_enterprise_desktop
novellsuse_linux_enterprise_workstation_extension
opensuseevergreen
opensuseopensuse

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://localhost/LoadMP4.swf?file=crash4000368.flv
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/37879.zip
  • Detect delivery of malicious FLV files containing Nellymoser-encoded audio (audio format tag byte 0x68) with oversized SoundData payloads (~0x440 bytes of 0xEE) served with Content-Type video/x-flv, which triggers the heap buffer overflow in Adobe Flash Player.
  • Monitor HTTP responses serving both a .swf and a .flv file in the same session with Cache-Control: no-cache, no-store and Pragma: no-cache headers, which matches the Metasploit exploit delivery pattern for CVE-2015-3043/CVE-2015-3113.
  • Flag Adobe Flash Player versions below 13.0.0.281 (Windows/OS X) or below 11.2.202.457 (Linux) as vulnerable to CVE-2015-3043; also flag 14.x through 17.x before 17.0.0.169.
  • CVE-2015-3113 is a regression to the same root cause as CVE-2015-3043; detections and signatures for one are effective against the other. Treat both CVEs as the same exploit family targeting Nellymoser audio decoding in Flash.
  • The exploit crash manifests as a heap-based buffer overflow at a movaps instruction writing to an unmapped region just past the committed heap; look for Flash Player crash dumps with this instruction pattern.
  • The exploit HTML template embeds a SWF via an object/embed tag passing FlashVars parameters 'sh', 'pl', and 'os'; inspect page source for these specific FlashVar names as an indicator of exploit kit delivery.
  • ·The exploit targets only 32-bit (ARCH_X86) Flash Player processes; 64-bit Flash in Chrome on Linux may crash differently (movaps fault) rather than achieving code execution.
  • ·The Metasploit module targets Windows 7 SP1, Windows 8.1, Linux Mint 'Rebecca', and Ubuntu 14.04.2 LTS with specific Flash versions (18.0.0.160 on Windows, 11.2.202.466 on Linux); exploitation success varies outside these tested configurations.
  • ·Google Chrome and Internet Explorer on Windows 8.x auto-update Flash to the patched version 17.0.0.169; these browser/OS combinations may not be exploitable if auto-update is functioning.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.