CVE-2015-7645
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
The impacted product is end-of-life and should be disconnected if still in use.
Adobe Flash Player has a vulnerability that allows attackers to run malicious code on your computer by tricking you into opening a specially crafted Flash file. This was actively exploited in real attacks during October 2015.
Remote code execution vulnerability in Adobe Flash Player (versions 18.x-18.0.0.252, 19.x-19.0.0.207 on Windows/OS X; 11.x-11.2.202.535 on Linux) triggered via malicious SWF file delivery. Attack requires user interaction to open the crafted file; successful exploitation results in arbitrary code execution with user privileges.
The full analysis of this CVE is available in Portuguese →