CVE-2015-3080
published 2015-05-13CVE-2015-3080: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on…
PriorityP272critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
56.55%
99.0th percentile
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 17.0.0.144 | — |
| adobe | air_sdk | <= 17.0.0.144 | — |
| adobe | air_sdk_compiler | <= 17.0.0.144 | — |
| adobe | flash_player | <= 13.0.0.264 | — |
| adobe | flash_player | <= 11.2.202.475 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
52 17 96 02 00 04 03 26 -> 17 17 17 17 17 17 17 17
- →Look for SWF files exploiting DisplacementMapFilter.mapBitmap property via AS2 with a custom/overridden BitmapData constructor — the exploit overrides flash.display.BitmapData with a custom class (MyBitmapData) to trigger the use-after-free. ↗
- →Detect SWF files containing AS2 bytecode where the BitmapData constructor is overridden (flash.display.BitmapData reassigned to a custom class) combined with DisplacementMapFilter usage and getPixel32 calls with a custom valueOf object. ↗
- →Crash/exploit indicator: controlled EAX value of 0x41424344 at dereference in BitmapData.getPixel32 code path (address 6D2BFA83); monitor Flash Player crashes with EAX=0x41424344. ↗
- →Exploit uses a large array of 0x41424344 values (0xC8/4 = 50 entries) stored in tabStops of TextFormat objects for heap manipulation — detect SWF files allocating large TextFormat arrays with identical integer tabStop values. ↗
- →The exploit SWF requires manual byte patching at offset 0x90F — forensic analysis of suspicious SWF files should check for NOP-sled-like sequences of 0x17 (actionPOP) bytes at that offset in the AS2 bytecode. ↗
- ·The exploit was developed and tested against a specific Flash version (16.0.0.305) on Chrome 40.0.2214.111 on Win7 SP1 x64; crash addresses (e.g., 6D2BFA83, 6D2D3FBB) are version/ASLR-dependent and will differ across Flash builds. ↗
- ·The researcher noted uncertainty about ASLR bypass feasibility: the exploit may not be reliably weaponizable if a virtual function dereference is required. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h269-r68v-hpf3: Use-after-free vulnerability in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17
CVE-2015-3080 [HIGH] GHSA-h269-r68v-hpf3: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.
OSV
CVE-2015-3080: Use-after-free vulnerability in Adobe Flash Player before 13
osv·2015-05-13·CVSS 10.0
CVE-2015-3080 [CRITICAL] CVE-2015-3080: Use-after-free vulnerability in Adobe Flash Player before 13
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-09
vendor_redhat·2015-05-12·CVSS 10.0
CVE-2015-3080 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-09
flash-plugin: multiple code execution issues fixed in APSB15-09
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.
No detection rules found.
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB15-09
bugzilla·2015-05-13·CVSS 10.0
CVE-2015-3078 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-09
flash-plugin: multiple code execution issues fixed in APSB15-09
Adobe Security Bulletin APSB15-09 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB15-09:
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2015-3078, CVE-2015-3089, CVE-2015-3090, CVE-2015-3093).
These updates resolve a heap overflow vulnerability that could lead to code execution (CVE-2015-3088).
These updates resolve validation bypass issues that could be exploited to write arbitrary data to the file system under user permissions (CVE-2015-3082, CVE-2015-3083, CVE-2015-3085).
These updates resolve an integer overflow vulnerability that could lead to c
Zscaler
Zscaler detects Flash Player Vulnerabilities | 05-21-2015
blogs_zscaler
Zscaler detects Flash Player Vulnerabilities | 05-21-2015
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1005.htmlhttp://www.securityfocus.com/bid/74608http://www.securitytracker.com/id/1032285https://helpx.adobe.com/security/products/flash-player/apsb15-09.htmlhttps://security.gentoo.org/glsa/201505-02https://www.exploit-db.com/exploits/37853/http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1005.htmlhttp://www.securityfocus.com/bid/74608http://www.securitytracker.com/id/1032285https://helpx.adobe.com/security/products/flash-player/apsb15-09.htmlhttps://security.gentoo.org/glsa/201505-02https://www.exploit-db.com/exploits/37853/
2015-05-13
Published