CVE-2015-0311
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
The impacted product is end-of-life and should be disconnected if still in use.
Adobe Flash Player had a security flaw that let attackers run malicious code on your computer just by visiting a compromised website. This was a serious problem because Flash was widely used in browsers.
An unspecified remote code execution vulnerability in Adobe Flash Player (versions 13.0.0.262 and earlier on Windows/OS X, 11.2.202.438 on Linux, and 14.x-16.0.0.287 across platforms) allowed unauthenticated remote attackers to execute arbitrary code through unknown attack vectors, with active exploitation documented in January 2015.
The full analysis of this CVE is available in Portuguese →