cbcvebase.
CVE-2015-5123
published 2015-07-14

CVE-2015-5123: Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS…

PriorityP183critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-04
Exploited in the wild
EPSS
18.49%
96.9th percentile
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

Affected

15 ranges
VendorProductVersion rangeFixed in
adobeflash_player11.0 – 11.2.202.481
adobeflash_player13.0 – 13.0.0.302
adobeflash_player18.0 – 18.0.0.203
adobeflash_player_desktop_runtime18.0 – 18.0.0.203
opensuseevergreen
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_eus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
suselinux_enterprise_desktop
suselinux_enterprise_desktop
suselinux_enterprise_workstation_extension

Detection & IOCsextracted from sources · hover to see the quote

hash31d03169b9742a0ff04e3d24bb448bbf
hashfcecd6b624bb50301a17d5aa423e135d
filenamerdws.exe
pathC:\ProgramData\wmiprivse.exe
registry\Software\Microsoft\Windows\CurrentVersion\Run
  • CVE-2015-5123 is a use-after-free triggered via a valueOf override on a freed Bitmap object in ActionScript 3; detect crafted SWF content invoking valueOf on BitmapData objects.
  • Post-exploitation, look for Flash plugin spawning child processes that perform network reconnaissance, indicative of hands-on-keyboard attacker activity following CVE-2015-5122/5123 exploitation.
  • Hunt for the registry run key value name 'adobeUpdate' pointing to wmiprivse.exe in C:\ProgramData as a persistence indicator for post-exploitation payloads dropped via this Flash exploit chain.
  • Payloads PlugX, Emdivi, and IsSpace dropped as rdws.exe (later renamed wmiprivse.exe) are linked to Chinese targeted intrusion operators exploiting this Flash vulnerability.
  • CVE-2015-5123 was integrated into the Angler Exploit Kit; monitor for Angler EK traffic patterns delivering Flash exploits.
  • ·The two in-the-wild sample hashes (31d03169... and fcecd6b6...) are attributed to CVE-2015-5122 (valueOf UAF on freed TextBox) by Zscaler; CVE-2015-5123 (valueOf UAF on freed Bitmap) is listed separately without dedicated sample hashes in the same source.
  • ·The CrowdStrike post-exploitation details (rdws.exe, wmiprivse.exe, adobeUpdate registry key) were confirmed to be associated with CVE-2015-5122 exploitation, not CVE-2015-5123, though both CVEs were exploited in the same campaign.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.