CVE-2015-5131
published 2015-08-14CVE-2015-5131: Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before…
PriorityP271critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
50.73%
98.8th percentile
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5132 and CVE-2015-5133.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 18.0.0.180 | — |
| adobe | air_sdk | <= 18.0.0.180 | — |
| adobe | air_sdk_compiler | <= 18.0.0.180 | — |
| adobe | flash_player | <= 18.0.0.209 | — |
| adobe | flash_player | <= 11.2.202.491 | — |
| opensuse | evergreen | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Crash occurs at instruction 'mov al,byte ptr [edx+eax]' inside FlashPlayer!WinMainSandboxed+0x572f0 (offset 0x0139a657), triggered by an overly large index value in EDX relative to a dynamically allocated buffer pointed to by EAX. ↗
- →The out-of-bounds read index (EDX) originates from offset 0x3453b8 in the malicious SWF file, one byte after the EAX memory region base offset 0x3453b7. Inspect SWF files for anomalously large index values at these offsets. ↗
- →The memory region under EAX is mapped PAGE_READWRITE / MEM_PRIVATE and the out-of-bounds access lands beyond its End Address (0x078ad000), producing an access violation (code c0000005). Monitor Flash Player processes for access violations at this symbol offset. ↗
- →Reliably reproduces with Adobe Flash Player Projector for Windows and Google Chrome for Windows; prioritize detection on those platforms. ↗
- ·CVE-2015-5131 is a distinct buffer overflow from CVE-2015-5132 and CVE-2015-5133, all three affecting the same Flash/AIR version ranges; ensure detections and patches target all three CVEs independently. ↗
- ·The crashing sample and original PoC file differ by only 13 bytes, meaning malicious SWF files may be nearly identical to benign ones; byte-level diffing or entropy analysis may be needed to distinguish them. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: multiple code execution flaws (APSB15-19)
vendor_redhat·2015-08-12·CVSS 10.0
CVE-2015-5131 [CRITICAL] flash-plugin: multiple code execution flaws (APSB15-19)
flash-plugin: multiple code execution flaws (APSB15-19)
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5132 and CVE-2015-5133.
Red Hat
flash-plugin: multiple code execution flaws (APSB15-19)
vendor_redhat·2015-08-12·CVSS 10.0
CVE-2015-5132 [CRITICAL] flash-plugin: multiple code execution flaws (APSB15-19)
flash-plugin: multiple code execution flaws (APSB15-19)
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5131 and CVE-2015-5133.
Red Hat
flash-plugin: multiple code execution flaws (APSB15-19)
vendor_redhat·2015-08-12·CVSS 10.0
CVE-2015-5133 [CRITICAL] flash-plugin: multiple code execution flaws (APSB15-19)
flash-plugin: multiple code execution flaws (APSB15-19)
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5131 and CVE-2015-5132.
GHSA
GHSA-xgpm-hq77-53g9: Buffer overflow in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-5133 [CRITICAL] CWE-119 GHSA-xgpm-hq77-53g9: Buffer overflow in Adobe Flash Player before 18
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5131 and CVE-2015-5132.
GHSA
GHSA-h2j6-rj2w-2v6v: Buffer overflow in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-5131 [CRITICAL] CWE-119 GHSA-h2j6-rj2w-2v6v: Buffer overflow in Adobe Flash Player before 18
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5132 and CVE-2015-5133.
GHSA
GHSA-mv5r-33xg-53v7: Buffer overflow in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-5132 [CRITICAL] CWE-119 GHSA-mv5r-33xg-53v7: Buffer overflow in Adobe Flash Player before 18
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5131 and CVE-2015-5133.
OSV
CVE-2015-5131: Buffer overflow in Adobe Flash Player before 18
osv·2015-08-14·CVSS 10.0
CVE-2015-5131 [CRITICAL] CVE-2015-5131: Buffer overflow in Adobe Flash Player before 18
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5132 and CVE-2015-5133.
OSV
CVE-2015-5133: Buffer overflow in Adobe Flash Player before 18
osv·2015-08-14·CVSS 10.0
CVE-2015-5133 [CRITICAL] CVE-2015-5133: Buffer overflow in Adobe Flash Player before 18
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5131 and CVE-2015-5132.
OSV
CVE-2015-5132: Buffer overflow in Adobe Flash Player before 18
osv·2015-08-14·CVSS 10.0
CVE-2015-5132 [CRITICAL] CVE-2015-5132: Buffer overflow in Adobe Flash Player before 18
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5131 and CVE-2015-5133.
No detection rules found.
http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1603.htmlhttp://www.securityfocus.com/bid/76284http://www.securitytracker.com/id/1033235https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://helpx.adobe.com/security/products/flash-player/apsb15-19.htmlhttps://security.gentoo.org/glsa/201508-01https://www.exploit-db.com/exploits/37856/http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1603.htmlhttp://www.securityfocus.com/bid/76284http://www.securitytracker.com/id/1033235https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://helpx.adobe.com/security/products/flash-player/apsb15-19.htmlhttps://security.gentoo.org/glsa/201508-01https://www.exploit-db.com/exploits/37856/
2015-08-14
Published