Vulnerability record · CVE-2015-0313 · published 2 February 2015
CVE-2015-0313: Adobe Flash Player use-after-free allows remote code execution
Adobe · Flash Player
Adobe Flash Player contains a use-after-free (CWE-416) flaw reachable through unspecified vectors. It affects Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X, and before 11.2.202.442 on Linux. It matters because it was exploited in the wild in February 2015 and permits remote code execution.
Description
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, confirmed in-the-wild exploitation, KEV listing and very high EPSS probability make this an urgent, actively exploited remote code execution flaw.
What it is
Adobe Flash Player contains a use-after-free (CWE-416) flaw reachable through unspecified vectors. It affects Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X, and before 11.2.202.442 on Linux. It matters because it was exploited in the wild in February 2015 and permits remote code execution.
Impact
An attacker can execute arbitrary code in the context of the affected Flash Player process, giving full compromise of confidentiality, integrity and availability on the victim host.
Attack surface
Reached remotely over the network with no authentication and no user interaction per the CVSS vector (AV:N/AC:L/PR:N/UI:N), typically by delivering crafted Flash content to a browser. The description does not specify the exact vectors.
Exploitation
Exploited in the wild in February 2015 per the description, listed in CISA KEV since 2022-04-13, and public exploit references exist (Packet Storm, Exploit-DB). EPSS 30-day probability is 0.95266 (99.862 percentile).
What to do
- Patch to Flash Player 13.0.0.269 or later, 16.0.0.305 or later on Windows/OS X, and 11.2.202.442 or later on Linux; apply the linked Microsoft and Adobe updates.
- Because Flash Player is end-of-life, remove or disconnect the product if it is still in use, per CISA KEV required action.
- Disable or block Flash content in browsers and remove the Flash plugin from endpoints where it is not strictly required.
- Apply the referenced SUSE/openSUSE security updates on affected Linux distributions.
Detection
- Hunt for Flash Player versions below the fixed thresholds (13.0.0.269, 16.0.0.305, 11.2.202.442) across endpoints.
- Monitor for browser or Flash Player processes spawning unexpected child processes or making anomalous outbound connections.
- Review proxy and IDS/IPS logs for delivery of Flash (.swf) content from untrusted or newly seen hosts.
- Check for the public exploit artifacts referenced in Packet Storm and Exploit-DB against endpoint telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-0313 to the Known Exploited Vulnerabilities catalog on 13 April 2022 as "Adobe Flash Player Use-After-Free Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 4 May 2022.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-0313 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-0313), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.