cbcvebase.
CVE-2015-5122
published 2015-07-14

CVE-2015-5122: Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and…

PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-04
Exploited in the wild
EPSS
93.69%
99.8th percentile
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.

Affected

16 ranges
VendorProductVersion rangeFixed in
adobeflash_player11.0 – 11.2.202.481
adobeflash_player13.0 – 13.0.0.302
adobeflash_player18.0 – 18.0.0.203
adobeflash_player18.0 – 18.0.0.204
adobeflash_player_desktop_runtime18.0 – 18.0.0.203
opensuseevergreen
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_eus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
suselinux_enterprise_desktop
suselinux_enterprise_desktop
suselinux_enterprise_workstation_extension

Detection & IOCsextracted from sources · hover to see the quote

hash31d03169b9742a0ff04e3d24bb448bbf
hashfcecd6b624bb50301a17d5aa423e135d
hash319500B2C792AEE6CD8EF8EE87D9DC1E
hash723DB4F13E98364098D76B925EA197F9ECD5309B
hash27439ADAA07F5AD16EB8039C16ECEB4E71F6358E7FC13AC645E8878DA8C3E77E
filenamemovie.swf
path%TEMP%\Rdws.exe
path%TEMP%\FASAP.DAT
path%TEMP%\FASAPI.bat
path%TEMP%\FASAPI.bin
ip172.246.109.27
url//STravel.asp
url//SJobs.asp
url//SSports.asp
url//SWeather.asp
  • The exploit SWF file (movie.swf) uses ZWS compression to evade AV; scan for ZWS-compressed SWF files delivered from web pages as a detection signal.
  • IsSpace drops payload to %TEMP%\Rdws.exe and executes via WinExec; alert on process creation of Rdws.exe from a temp directory.
  • IsSpace uses a DLL side-loading technique via sysprep.exe loading a dropped CryptBase.dll; monitor for CryptBase.dll loaded from %windir%\system32\sysprep\ when not expected.
  • CVE-2015-5122 exploits were rapidly weaponized and added to exploit kits (e.g., Angler) following the Hacking Team leak; prioritize blocking/patching Flash in EK-exposed environments.
  • ·The two in-the-wild MD5 hashes (31d03169... and fcecd6b6...) are attributed to CVE-2015-5122 exploit samples by Zscaler but no further file metadata is provided in the source.
  • ·The IsSpace payload (MD5: 319500B2C792AEE6CD8EF8EE87D9DC1E) has a compile timestamp of 2014-11-14, predating the CVE-2015-5122 exploit delivery; the malware infrastructure may have been active for months before this campaign.
  • ·The C2 IP 172.246.109.27 is hardcoded in this specific IsSpace sample; other samples or campaigns may use different infrastructure.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.