cbcvebase.
CVE-2015-3089
published 2015-05-13

CVE-2015-3089: Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172…

PriorityP266critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
47.62%
98.7th percentile
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3078, CVE-2015-3090, and CVE-2015-3093.

Affected

21 ranges
VendorProductVersion rangeFixed in
adobeair<= 17.0.0.144
adobeair_sdk<= 17.0.0.144
adobeair_sdk_compiler<= 17.0.0.144
adobeflash_player<= 13.0.0.264
adobeflash_player<= 11.2.202.475
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://localhost/PlayManifest.swf?file=gen.mpd
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/37845.zip
filenamePlayManifest.swf
filenamegen.mpd
filenamePlayManifest.as
  • Crash occurs at instruction 'mov dword ptr ds:[eax+D0],ecx' within pepflashplayer.dll, triggered by loading a malformed MPD file via a SWF — monitor for Flash crashes at this offset pattern.
  • Vulnerability is triggered by loading a malformed/malicious MPD (MPEG-DASH manifest) file through Flash Player — inspect HTTP traffic for .mpd files loaded by SWF content.
  • Root cause is an uninitialized stack variable during MPD parsing in Flash Player — look for Flash Player process crashes or memory corruption events associated with MPD file parsing.
  • ·Reproduction requires hosting both the SWF and MPD files on a web server and loading via a specific URL query parameter; exploit is not self-contained.
  • ·Crash was confirmed on Win7 x64 SP1 with Chrome 32-bit using Flash 17.0.0.134; behavior on other platforms may differ.
  • ·Compilation of the PoC SWF requires mxmlc with Flash Player 14.0 target and playerglobals.swc v14.0 or newer.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.