cbcvebase.
CVE-2015-7645
published 2015-10-15

CVE-2015-7645: Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to…

PriorityP192high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
68.40%
99.3th percentile
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.

Affected

19 ranges
VendorProductVersion rangeFixed in
adobeflash_player<= 11.2.202.535
adobeflash_player
adobeflash_player
adobeflash_player18.0.0.160 – 18.0.0.252
opensuseevergreen
opensuseopensuse
opensuseopensuse
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_from_rhui
redhatenterprise_linux_server_from_rhui
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
suselinux_enterprise_desktop
suselinux_enterprise_desktop
suselinux_enterprise_workstation_extension

Detection & IOCsextracted from sources · hover to see the quote

hashc42a0d50eac9399914090f1edc2bda9ac1079edff4528078549c824c4d023ff9
hash45a4a376cb7a36f8c7851713c7541cb7e347dafb08980509069a078d3bcb1405
hash5dd3066a8ee3ab5b380eb7781c85e4253683cd7e3eee1c29013a7a62cd9bef8c
hashfa8b4f64bff799524f6059c3a4ed5d169e9e7ef730f946ac7ad8f173e8294ed8
hash3ff1332a84d615a242a454e5b29f08143b1a89ac9bd7bfaa55ba0c546db10e4b
hash3bb47f37e16d09a7b9ba718d93cfe4d5ebbaecd254486d5192057c77c4a25363
domainversiontask[.]com
domainpostlkwarn[.]com
domainapptaskserver[.]com
domainappservicegroup[.]com
domainjoshel[.]com
domainuniquecorpind[.]com
domainerteilend-taendelt.sewnydine[.]com
domainrepersuasionboldoblique.classactoutlet[.]com
ip104.129.192.32
domainayh2m57ruxjtwyd5.stopmigrationss[.]com
domainayh2m57ruxjtwyd5.starswarsspecs[.]com
domainayh2m57ruxjtwyd5.malerstoniska[.]com
domainayh2m57ruxjtwyd5.blindpayallfor[.]com
ip95.128.181.195
ip109.70.26.37
ip194.85.61.76
domainflat.splo1t[.]ru
ip188.127.239.164
domainsanliurfapastanesi[.]com
ip95.173.190.210
domainwesalerx[.]xyz
ip46.148.18.100
domaintaigastyle[.]ru
ip37.140.192.180
domainflickstudio[.]com
ip103.21.59.22
domainxmest.web-zolotareva[.]ru
ip82.146.36.185
domainchaukakau[.]ru
ip62.173.143.242
domainzemli72.chaukakau[.]ru
domainavatar77[.]ru
domainecodeva[.]ru
domainturizmkirov[.]ru
domainnew.turizmkirov[.]ru
domaini-tem[.]ru
domainvsedveri33[.]ru
ip81.177.165.33
domainmediaopt33[.]ru
domaingaja24[.]pl
ip91.234.146.241
domainavtoreliv[.]com.ua
ip91.234.34.80
domainrecords.karika[.]in.ua
filenameOperation_in_Mosul.rtf
filenameNASAMS.doc
filenameProgramm_Details.doc
filenameDGI2017.doc
filenameOlympic-Agenda-2020-20-20-Recommendations.doc
filenameARM-NATO_ENGLISH_30_NOV_2016.doc

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.