Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 74.4%; technical severity is CVSS 9.8.
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.
Who should care
- Teams operating Flash Player, Suse Linux Enterprise Desktop, Suse Linux Enterprise Workstation Extension +8 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Flash Player, Suse Linux Enterprise Desktop, Suse Linux Enterprise Workstation Extension +8 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Adobe Security patch APSB15-06
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-787
- Affected versions
- Adobe Flash Player (End Excluding 11.2.202.457 | End Excluding 13.0.0.281 | Start Including 14.0.0.125, End Excluding 17.0.0.169); Novell Suse Linux Enterprise Desktop (Version 11.0 | Version 12.0); Novell Suse Linux Enterprise Workstation Extension (Version 12.0); Opensuse Evergreen (Version 11.4); Opensuse Opensuse (Version 13.1 | Version 13.2); Redhat Enterprise Linux Desktop (Version 5.0 | Version 6.0); Redhat Enterprise Linux Eus (Version 6.6); Redhat Enterprise Linux Server (Version 5.0 | Version 6.0)
- Fixed versions
- Adobe Flash Player (Fixed from 11.2.202.457, 13.0.0.281, 17.0.0.169)
- Published
- 14 April 2015
- Attack vector
- Network
- Privileges required
- None
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 74.4%
- Signal calculated at 82
External references
- Red Hat Third-party advisory RHSA 2015 0813
- CISA Government advisory CVE-2015-3043
- GitHub Technical reference
- Lists Opensuse Third-party advisory Msg00010
- Lists Opensuse Third-party advisory Msg00011
- Lists Opensuse Third-party advisory Msg00012
- Lists Opensuse Third-party advisory Msg00013
- Securityfocus Third-party advisory
- Securitytracker Third-party advisory 1032105
- Security Gentoo Third-party advisory 201504 07
- Exploit information from www.exploit-db.com