CVE-2015-7645highunder attackransomware

CVE-2015-7645

Published · Updated

83Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.8epss 65%
from disclosure to weapon4 days
Published on NVDOct 15
1st PoC+4d
CISA KEV+2331d
exploitation probability
65%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
3 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
5 products
Red Hat Enterprise Linux Desktop Supplementary (v. 5) · Red Hat Enterprise Linux Desktop Supplementary (v. 6) · Red Hat Enterprise Linux Server Supplementary (v. 5) · Red Hat Enterprise Linux Server Supplementary (v. 6) · Red Hat Enterprise Linux Workstation Supplementary (v. 6)
Action required by CISAfederal deadline: 2022-03-24

The impacted product is end-of-life and should be disconnected if still in use.

In short

Adobe Flash Player has a vulnerability that allows attackers to run malicious code on your computer by tricking you into opening a specially crafted Flash file. This was actively exploited in real attacks during October 2015.

Technical detail

Remote code execution vulnerability in Adobe Flash Player (versions 18.x-18.0.0.252, 19.x-19.0.0.207 on Windows/OS X; 11.x-11.2.202.535 on Linux) triggered via malicious SWF file delivery. Attack requires user interaction to open the crafted file; successful exploitation results in arbitrary code execution with user privileges.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.