CVE-2015-3104
published 2015-06-10CVE-2015-3104: Integer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe…
PriorityP276critical10CVSS 2.0
AVNACLAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
5.75%
92.2th percentile
Integer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allows attackers to execute arbitrary code via unspecified vectors.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 17.0.0.144 | — |
| adobe | air | <= 17.0.0.172 | — |
| adobe | air_sdk | <= 17.0.0.172 | — |
| adobe | air_sdk_compiler | <= 17.0.0.172 | — |
| adobe | flash_player | <= 11.2.202.460 | — |
| adobe | flash_player | <= 13.0.0.289 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
0x00905a4d
bytes↗
0x6230306e
- →Exploit allocates a large heap spray array (MAX_ARRAY = 81920 ByteArray objects of 0x10 bytes each) and then triggers an integer overflow in Adobe Flash Player's Shader input handling to corrupt a ByteArray length to 0x16000000 or 0xffffffff, enabling arbitrary read/write primitives. ↗
- →Exploit identifies the corrupted ByteArray by scanning for length != 0x10 among even-indexed entries starting at index MAX_ARRAY/2, then uses it to achieve arbitrary memory read/write. Detect Flash processes with anomalously large ByteArray allocations (0x16000000 or 0xffffffff bytes). ↗
- →Exploit writes a ROP chain and payload to fixed heap addresses 0x1a000000, 0x1a100000, 0x1a200000 via heap spray targeting base address 0x16000000. Memory allocations at these fixed addresses in a Flash process are a strong indicator of exploitation. ↗
- →Exploit uses VirtualProtect ROP chain (PUSHAD # RETN gadget) to make shellcode memory executable, then jumps to shellcode via JMP ESP gadget. Monitor Flash Player child processes or memory permission changes (RWX pages) as a detection signal. ↗
- →Exploit drops and executes a Meterpreter payload (pwnd.exe) written to heap address 0x1a100000 and decoded from Base64. Detect Base64-encoded PE files embedded in SWF/Flash content or unexpected executable writes from Flash Player processes. ↗
- →Exploit class is named 'ShaderInputOverflow' and abuses the Flash Shader/ShaderInput API to trigger the integer overflow. SWF files containing ShaderInput manipulation with large channel/width/height values should be treated as suspicious. ↗
- ·The ROP gadget offsets are hardcoded relative to NPSWF32Base (the Flash Player DLL base address) and are specific to the Flash Player version targeted by this exploit. They will not be valid for other versions. ↗
- ·The heap spray targets fixed base address 0x16000000 for ByteArray objects and 0x1a000000 for the ROP/payload region; ASLR or differing system memory layouts may cause these addresses to vary, reducing reliability of address-based detection. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9j6v-gvm6-rm3f: Integer overflow in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17
CVE-2015-3104 [HIGH] GHSA-9j6v-gvm6-rm3f: Integer overflow in Adobe Flash Player before 13
Integer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allows attackers to execute arbitrary code via unspecified vectors.
OSV
CVE-2015-3104: Integer overflow in Adobe Flash Player before 13
osv·2015-06-10·CVSS 10.0
CVE-2015-3104 [CRITICAL] CVE-2015-3104: Integer overflow in Adobe Flash Player before 13
Integer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allows attackers to execute arbitrary code via unspecified vectors.
VulnCheck
Adobe Flash Player, AIR, and AIR SDK Unspecified Arbitrary Code Execution
vulncheck·2015·CVSS 10.0
CVE-2015-3104 [CRITICAL] Adobe Flash Player, AIR, and AIR SDK Unspecified Arbitrary Code Execution
Adobe Flash Player, AIR, and AIR SDK Unspecified Arbitrary Code Execution
Integer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allows attackers to execute arbitrary code via unspecified vectors.
Affected: Adobe air
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://securelist.com/it-threat-evolution-q2-2015/71610/;
Red Hat
flash-plugin: multiple code execution issues fixed in APSB15-11
vendor_redhat·2015-06-09·CVSS 10.0
CVE-2015-3104 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-11
flash-plugin: multiple code execution issues fixed in APSB15-11
Integer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allows attackers to execute arbitrary code via unspecified vectors.
No detection rules found.
Zscaler
Zscaler discovers Flash Player Vulnerabilities | 06-09-2015
blogs_zscaler
Zscaler discovers Flash Player Vulnerabilities | 06-09-2015
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
CVE-2015-3100 CVE-2015-3103 CVE-2015-3104 CVE-2015-3105 CVE-2015-3106 CVE-2015-3107 flash-plugin: multiple code execution issues fixed in APSB15-11
bugzilla·2015-06-09·CVSS 10.0
CVE-2015-3100 [CRITICAL] CVE-2015-3100 CVE-2015-3103 CVE-2015-3104 CVE-2015-3105 CVE-2015-3106 CVE-2015-3107 flash-plugin: multiple code execution issues fixed in APSB15-11
CVE-2015-3100 CVE-2015-3103 CVE-2015-3104 CVE-2015-3105 CVE-2015-3106 CVE-2015-3107 flash-plugin: multiple code execution issues fixed in APSB15-11
Adobe Security Bulletin APSB15-11 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB15-11:
These updates resolve a stack overflow vulnerability that could lead to code execution (CVE-2015-3100).
These updates resolve an integer overflow vulnerability that could lead to code execution (CVE-2015-3104).
These updates resolve a memory corruption vulnerability that could lead to code execution (CVE-2015-3105).
These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2015-3103, CVE-2015-3
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00011.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1086.htmlhttp://www.securityfocus.com/bid/75081http://www.securitytracker.com/id/1032519https://helpx.adobe.com/security/products/flash-player/apsb15-11.htmlhttps://security.gentoo.org/glsa/201506-01http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00011.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1086.htmlhttp://www.securityfocus.com/bid/75081http://www.securitytracker.com/id/1032519https://helpx.adobe.com/security/products/flash-player/apsb15-11.htmlhttps://security.gentoo.org/glsa/201506-01
2015-06-10
Published
Exploited in the wild