cbcvebase.
CVE-2015-3090
published 2015-05-13

CVE-2015-3090: Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172…

PriorityP180critical10CVSS 2.0
AVNACLAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
87.30%
99.7th percentile
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3078, CVE-2015-3089, and CVE-2015-3093.

Affected

21 ranges
VendorProductVersion rangeFixed in
adobeair<= 17.0.0.144
adobeair_sdk<= 17.0.0.144
adobeair_sdk_compiler<= 17.0.0.144
adobeflash_player<= 13.0.0.264
adobeflash_player<= 11.2.202.475
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player

Detection & IOCsextracted from sources · hover to see the quote

pathdata/exploits/CVE-2015-3090/msf.swf
otherContent-Type: application/x-shockwave-flash
  • The exploit delivers a malicious SWF file via HTTP with Content-Type 'application/x-shockwave-flash' and Cache-Control/Pragma no-cache headers; detect HTTP responses serving .swf files with these no-cache directives from exploit kit infrastructure.
  • The exploit is triggered by manipulating the 'width' attribute of a ShaderJob after starting it with the same Bitmap object as both src and destination; look for ActionScript/SWF content that sets up ShaderJob with identical src/destination Bitmap objects.
  • CVE-2015-3090 was exploited in the wild by the Angler Exploit Kit; correlate Flash exploit activity with Angler EK network indicators.
  • The Metasploit module targets x86 architecture on Windows 7 SP1, Windows 8.1 (IE11 or Firefox) and Linux (Firefox); scope detections to 32-bit Flash processes in these browser/OS combinations for this CVE.
  • ·Affected versions span a wide range: Flash Player before 13.0.0.289, 14.x–17.x before 17.0.0.188 (Windows/OS X), before 11.2.202.460 (Linux), and Adobe AIR/AIR SDK/AIR SDK & Compiler before 17.0.0.172; ensure version checks cover all branches.
  • ·CVE-2015-3090 is a distinct vulnerability from CVE-2015-3078, CVE-2015-3089, and CVE-2015-3093, all fixed in APSB15-09; do not conflate detection signatures across these four CVEs.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.