⚠ Actively exploited
Added to CISA KEV on 2022-04-13. Federal agencies required to patch by 2022-05-04. Required action: The impacted product is end-of-life and should be disconnected if still in use..

CVE-2015-5122

CWE-416Use After Free13 documents11 sources
Severity
9.8CRITICAL
EPSS
92.8%
top 0.24%
CISA KEV
KEV
Added 2022-04-13
Due 2022-05-04
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJul 14
KEV addedApr 13
KEV dueMay 4
Latest updateMay 13
CISA Required Action: The impacted product is end-of-life and should be disconnected if still in use.

Description

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages9 packages

NVDadobe/flash_player13.013.0.0.302+3
NVDadobe/flash_player_desktop_runtime18.018.0.0.203
Ubuntuflashplugin-nonfree< 11.2.202.481ubuntu0.14.04.2

Also affects: Enterprise Linux 6.6

🔴Vulnerability Details

5
GHSA
GHSA-9h3m-vp3m-35pw: Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 132022-05-13
Project0
Attacking ECMAScript Engines with Redefinition - Project Zero2015-08-01
CVEList
CVE-2015-5122: Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 132015-07-14
OSV
CVE-2015-5122: Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 132015-07-14
VulnCheck
Adobe Flash Player Use-After-Free Vulnerability2015

💥Exploits & PoCs

1
Exploit-DB
Adobe Flash - opaqueBackground Use-After-Free (Metasploit)2015-07-13

📋Vendor Advisories

2
CISA
Adobe Flash Player Use-After-Free Vulnerability2022-04-13
Red Hat
flash-plugin: two code execution issues in APSA15-04 / APSB15-182015-07-10

🕵️Threat Intelligence

2
Unit42
Watering Hole Attack on Aerospace Firm Exploits CVE-2015-5122 to Install IsSpace Backdoor2015-07-20
Unit42
Watering Hole Attack on Aerospace Firm Exploits CVE-2015-5122 to Install IsSpace Backdoor2015-07-20

💬Community

1
Bugzilla
CVE-2015-5122 CVE-2015-5123 flash-plugin: two code execution issues in APSA15-04 / APSB15-182015-07-12
CVE-2015-5122 (CRITICAL CVSS 9.8) | Use-after-free vulnerability in the | cvebase.io