Skip to content
COOEY

EXPOSURES › CVE-2015-5123

CVE-2015-5123

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2015-5123 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatchedrce

Adobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, and the product's end-of-life status left it perpetually unpatched.

Adobe Flash Player contained a use-after-free vulnerability in its BitmapData class that enabled remote code execution. Because Flash reached end-of-life in December 2020, no patches were issued, leaving any remaining installations perpetually vulnerable to unpatched exploits. DIB organizations must ensure Flash is completely removed from all systems to avoid exposure to actively exploited vulnerabilities.

Shame score — The product was end-of-life with no patches, leaving known critical vulnerabilities unpatched and perpetually exploitable.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized