EXPOSURES › CVE-2015-5122
CVE-2015-5122
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, and the product's end-of-life status meant it remained perpetually unpatched and exploitable.
Adobe Flash Player suffered a use-after-free vulnerability enabling remote code execution, but its December 2020 end-of-life meant no patches were issued, leaving installations perpetually vulnerable. DIB organizations must ensure discontinued software is fully removed to avoid exposure to unpatched exploits that can lead to system compromise and compliance failures.
Shame score — The product was end-of-life with no patches, making the vulnerability perpetually exploitable and representing negligent software maintenance.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |