Skip to content
COOEY

EXPOSURES › CVE-2015-0310

CVE-2015-0310

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2015-0310 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 exploited-in-wildunpatchedrce

Adobe Flash Player's ASLR bypass vulnerability allowed attackers to bypass memory randomization protections, enabling remote code execution.

The vulnerability in Adobe Flash Player allowed attackers to bypass ASLR protections, leading to remote code execution. DIB organizations must ensure Flash Player is completely removed from all systems, as its end-of-life status means no patches exist for any remaining vulnerabilities. This failure highlights the critical risk of running end-of-life software, which remains a perpetual security liability.

Shame score — Adobe shipped a product with a critical ASLR bypass vulnerability that was actively exploited in the wild, and the product's end-of-life status left it perpetually vulnerable to unpatched exploits.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized