EXPOSURES › CVE-2015-0310
CVE-2015-0310
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Flash Player's ASLR bypass vulnerability allowed attackers to bypass memory randomization protections, enabling remote code execution.
The vulnerability in Adobe Flash Player allowed attackers to bypass ASLR protections, leading to remote code execution. DIB organizations must ensure Flash Player is completely removed from all systems, as its end-of-life status means no patches exist for any remaining vulnerabilities. This failure highlights the critical risk of running end-of-life software, which remains a perpetual security liability.
Shame score — Adobe shipped a product with a critical ASLR bypass vulnerability that was actively exploited in the wild, and the product's end-of-life status left it perpetually vulnerable to unpatched exploits.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |