cbcvebase.
CVE-2015-7652
published 2015-11-11

CVE-2015-7652: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR…

PriorityP262critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
24.60%
97.6th percentile
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via a crafted gridFitType property value, a different vulnerability than CVE-2015-7651, CVE-2015-7653, CVE-2015-7654, CVE-2015-7655, CVE-2015-7656, CVE-2015-7657, CVE-2015-7658, CVE-2015-7660, CVE-2015-7661, CVE-2015-7663, CVE-2015-8042, CVE-2015-8043, CVE-2015-8044, and CVE-2015-8046.

Affected

9 ranges
VendorProductVersion rangeFixed in
adobeair<= 19.0.0.213
adobeair<= 19.0.0.190
adobeair_sdk<= 19.0.0.213
adobeair_sdk_compiler<= 19.0.0.213
adobeflash_player<= 11.2.202.540
adobeflash_player<= 18.0.0.255
adobeflash_player
adobeflash_player
adobeflash_player

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39020.zip
  • CVE-2015-7652 is triggered via the TextField.gridFitType setter in Adobe Flash — look for ActionScript setting gridFitType to an object (rather than a string literal) whose toString callback frees the parent MovieClip, indicating UAF exploitation.
  • Affected component is Adobe Flash Player before 18.0.0.261 / 19.x before 19.0.0.245 (Windows/OS X) and before 11.2.202.548 (Linux); flag Flash Player processes at these versions handling SWF content that manipulates TextField.gridFitType.
  • ·The NVD source document is for CVE-2015-8043, not CVE-2015-7652 directly; CVE-2015-7652 is listed as a related but distinct UAF vulnerability sharing the same affected version ranges and product set.
  • ·The exploit-db PoC (EDB-39020) is attributed to CVE-2015-7652 via the TextField.gridFitType UAF vector; the PoC SWF/FLA files are bundled in the linked ZIP and should be treated as malicious samples for testing only.

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.