cbcvebase.
CVE-2015-3128
published 2015-07-09

CVE-2015-3128: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on…

PriorityP264critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
39.24%
98.4th percentile
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3118, CVE-2015-3124, CVE-2015-3127, CVE-2015-3129, CVE-2015-3131, CVE-2015-3132, CVE-2015-3136, CVE-2015-3137, CVE-2015-4428, CVE-2015-4430, and CVE-2015-5117.

Affected

25 ranges
VendorProductVersion rangeFixed in
adobeair<= 18.0.0.144
adobeair_sdk<= 18.0.0.144
adobeair_sdk_compiler<= 18.0.0.144
adobeflash_player<= 11.2.202.468
adobeflash_player<= 13.0.0.289
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/37860.zip
commandColor.setRGB(o) with o.valueOf deleting target_mc (tf.removeTextField())
  • Trigger pattern: AS2 Color constructor called with a MovieClip/TextField target, followed by Color.setRGB() with an object whose valueOf() callback removes the target (e.g. tf.removeTextField()) — monitor Flash content invoking this sequence.
  • Crash/exploitation occurs at flashplayer17_sa.exe offset 0x4B0724 (mov edx, [ecx]) when ecx == 0x3C (null-page dereference); crash telemetry or minidumps referencing this offset in Flash 17.0.0.169 are indicative of exploitation attempts.
  • Affected Flash version confirmed in PoC: Flash 17.0.0.169 on Chrome stable 42.0.2311.90, Win7 x64 SP1; presence of this Flash version in environment warrants priority patching and monitoring.
  • SWF files compiled with Flash CS5.5 containing AS2 Color UAF pattern (Color constructor + setRGB with valueOf callback that calls removeTextField) should be flagged during static or dynamic analysis.
  • ·CVE-2015-3128 is one of multiple use-after-free CVEs patched in the same Flash bulletin; the NVD source document references CVE-2015-3132 and lists CVE-2015-3128 only as a related sibling vulnerability — confirm the exploit-db entry is correctly mapped to CVE-2015-3128 before operationalizing.
  • ·The PoC reproduces on Flash 17.0.0.169; fixed versions per advisory are Flash before 13.0.0.302 (legacy branch) and 18.x before 18.0.0.203 on Windows/OS X, and before 11.2.202.481 on Linux — detection rules should account for the full affected version range.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.