EXPOSURES › CVE-2015-8651
CVE-2015-8651
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Flash Player's integer overflow vulnerability allowed remote code execution, and the product's end-of-life status left it perpetually unpatched and exploitable.
Adobe Flash Player suffered from an integer overflow vulnerability enabling remote code execution, a flaw that persisted due to the product's end-of-life status in December 2020. DIB organizations must care because unpatched, discontinued software remains a perpetual liability, especially when actively exploited in the wild. The takeaway is to eliminate legacy, unsupported software from the environment to prevent exploitation of known, unpatched vulnerabilities.
Shame score — Adobe shipped a discontinued product with known critical vulnerabilities that remained unpatched after end-of-life, and the flaw was actively exploited in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Integer overflow in Adobe Flash Player allows attackers to execute code.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |