Skip to content
COOEY

EXPOSURES › CVE-2015-0311

CVE-2015-0311

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2015-0311 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatchedransomware

Adobe Flash Player's unpatched RCE vulnerability remains a perpetual liability after its December 2020 end-of-life.

Adobe Flash Player reached end-of-life in December 2020 without further security patches, leaving any remaining installations perpetually vulnerable to unpatched exploits. DIB organizations must ensure Flash is completely removed from all systems to avoid exposure to actively exploited RCE vulnerabilities that could compromise network integrity and violate compliance requirements.

Shame score — Adobe's failure to patch known vulnerabilities before discontinuing Flash Player, combined with the product's continued presence in some environments, represents a negligent, avoidable security failure that perpetually exposes organizations to actively exploited RCE attacks.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized