cbcvebase.
CVE-2015-5548
published 2015-08-14

CVE-2015-5548: Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and…

PriorityP265critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
38.17%
98.4th percentile
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5544, CVE-2015-5545, CVE-2015-5546, CVE-2015-5547, CVE-2015-5549, CVE-2015-5552, and CVE-2015-5553.

Affected

5 ranges
VendorProductVersion rangeFixed in
adobeair<= 18.0.0.180
adobeair_sdk<= 18.0.0.180
adobeair_sdk_compiler<= 18.0.0.180
adobeflash_player<= 11.2.202.491
adobeflash_player<= 18.0.0.209

Detection & IOCsextracted from sources · hover to see the quote

hashe3f87b25c25db8f9ec3c975f8c1211cc
filenamesignal_sigsegv_7ffff637297a_8900_e3f87b25c25db8f9ec3c975f8c1211cc.swf
filenamee3f87b25c25db8f9ec3c975f8c1211cc.swf
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/37870.zip
  • The vulnerability is triggered via malformed SWF files exploiting XML handling in Adobe Flash Player. Monitor for SWF files causing SIGSEGV crashes with wild pointer dereference at rcx=0x303030303030300 (pattern of '0' bytes), indicative of controlled memory corruption.
  • The exploit primitive allows a wild pointer target to be incremented (read → increment → write-back pattern). Detection should look for Flash Player crashes involving a read-modify-write sequence on a controlled/wild pointer, particularly in XML processing code paths.
  • Crash originates from XML handling logic in Adobe Flash Player on Linux x64. Suspicious SWF files triggering XML-related memory corruption should be flagged for analysis.
  • ·CVE-2015-5548 is one of several memory corruption vulnerabilities (CVE-2015-5544, -5545, -5546, -5547, -5548, -5549, -5552, -5553) patched in the same Adobe Flash release. The NVD source references CVE-2015-5547 explicitly; the SWF PoC sample may relate to any one of these sibling CVEs.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.