cbcvebase.
CVE-2015-5119
published 2015-07-08

CVE-2015-5119: Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through…

PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
99.34%
99.9th percentile
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

Affected

19 ranges
VendorProductVersion rangeFixed in
adobeflash_player<= 11.2.202.468
adobeflash_player13.0.0.182 – 13.0.0296
adobeflash_player14.0.0.125 – 18.0.0.194
opensuseevergreen
opensuseopensuse
opensuseopensuse
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_from_rhui
redhatenterprise_linux_server_from_rhui
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
suselinux_enterprise_desktop
suselinux_enterprise_desktop
suselinux_enterprise_workstation_extension

Detection & IOCsextracted from sources · hover to see the quote

hash31d03169b9742a0ff04e3d24bb448bbf
hashfcecd6b624bb50301a17d5aa423e135d
hasha795deaa2d1c1f2d9426a8c28791111e0192ffad14d086b51bc61c8e16008b63
  • CVE-2015-5119 is a Use-After-Free in Adobe Flash Player's ByteArray class (AS3), triggered when crafted Flash content overrides a valueOf function — look for SWF files exploiting ByteArray valueOf overrides.
  • CVE-2015-5119 was rapidly integrated into Angler, Nuclear, Neutrino, and Fiddler exploit kits — network traffic associated with these EKs should be inspected for Flash exploit delivery.
  • A Flash exploit based on CVE-2015-5119 was integrated into Angler EK within hours of the Hacking Team data dump — treat any Angler EK traffic from July 2015 onward as potentially carrying this exploit.
  • The exploit targets Flash Player via major browsers (Chrome, Firefox, IE, Safari) and also via embedded SWF in Microsoft Office documents (2007/2010/2013) — monitor for Office documents with embedded SWF content.
  • The Underminer exploit kit uses cookie detection to prevent repeated exploit site visits — monitor for unusual cookie-setting behavior combined with Flash Player version profiling in HTTP traffic.
  • The Underminer exploit kit (which uses CVE-2015-5119) encrypts traffic with RSA prior to exploitation — look for encrypted non-standard traffic patterns preceding Flash exploit delivery.
  • The exploit was confirmed working on Windows XP and Windows 7 with the latest Flash 18 at the time; also supported OS X targeting — prioritize detection on these platforms.
  • The Chrome sandbox could be bypassed by chaining CVE-2015-5119 with an unpatched Windows kernel privilege escalation vulnerability — look for Flash exploit followed by kernel-level privilege escalation activity.
  • Tenable Plugin IDs 84641, 84642, 84667, and 84645 detect vulnerable Adobe Flash/AIR/Chrome versions affected by CVE-2015-5119 — use these for vulnerability scanning.
  • ·The two MD5 hashes (31d03169b9742a0ff04e3d24bb448bbf and fcecd6b624bb50301a17d5aa423e135d) are noted in the Zscaler post under CVE-2015-5122 (valueOf UAF in TextBox), not CVE-2015-5119 — verify before using as CVE-2015-5119 indicators.
  • ·The SHA-256 hash from Tenable/VirusTotal (a795deaa...) is associated with the Underminer exploit kit payload (Hidden Mellifera coin miner), not exclusively CVE-2015-5119 — confirm the specific exploit used before attributing.
  • ·The patched version of Flash Player is 18.0.0.203 for Windows and Mac — ensure detections distinguish between vulnerable (≤18.0.0.194) and patched versions.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.