EXPOSURES › CVE-2015-5123
CVE-2015-5123
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, and the product's end-of-life status left it perpetually unpatched.
Adobe Flash Player contained a use-after-free vulnerability in its BitmapData class that enabled remote code execution. Because Flash reached end-of-life in December 2020, no patches were issued, leaving any remaining installations perpetually vulnerable to unpatched exploits. DIB organizations must ensure Flash is completely removed from all systems to avoid exposure to actively exploited vulnerabilities.
Shame score — The product was end-of-life with no patches, leaving known critical vulnerabilities unpatched and perpetually exploitable.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |