Vulnerability record · CVE-2015-0336 · published 13 March 2015
CVE-2015-0336: Adobe Flash Player type confusion allows arbitrary code execution
Adobe · Flash Player
Adobe Flash Player contains an unspecified type confusion flaw that lets attackers execute arbitrary code. It affects Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X, and before 11.2.202.451 on Linux. The vulnerability is distinct from CVE-2015-0334 and carries a CVSS v2 base score of 9.3.
Description
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0334.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS v2 9.3 with a very high EPSS percentile and a public exploit make this a serious risk, though it is not in CISA KEV and the flaw description is thin.
What it is
Adobe Flash Player contains an unspecified type confusion flaw that lets attackers execute arbitrary code. It affects Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X, and before 11.2.202.451 on Linux. The vulnerability is distinct from CVE-2015-0334 and carries a CVSS v2 base score of 9.3.
Impact
An attacker can execute arbitrary code in the context of the affected Flash Player process, which typically means full compromise of the user's system. The CVSS vector indicates complete loss of confidentiality, integrity and availability.
Attack surface
The flaw is network-reachable (AV:N) with medium access complexity (AC:M) and requires no authentication (Au:N). Exploitation is consistent with a user visiting a crafted page or opening malicious Flash content, so user interaction is likely but the record does not state it explicitly.
Exploitation
CISA KEV does not list this CVE, but EPSS gives a 30-day probability of 0.70445 (99.356th percentile), indicating high predicted exploitation activity. A public Exploit-DB entry (36962) exists, and the Adobe advisory is tagged Patch and Vendor Advisory.
What to do
- Update Flash Player to 13.0.0.277 or later, 17.0.0.134 or later on Windows and OS X, and 11.2.202.451 or later on Linux per Adobe APSB15-05.
- Apply the referenced Red Hat, openSUSE and Gentoo updates where Flash Player is packaged.
- Disable or remove Flash Player where it is not required, and restrict browser plugins to trusted sites.
- Block or sandbox Flash content at the network and endpoint level to reduce exposure until patching completes.
Detection
- Monitor for Flash Player processes spawning unexpected child processes such as cmd.exe, powershell.exe or /bin/sh.
- Hunt for exploit artifacts matching Exploit-DB 36962 and for Flash content delivered from unusual or newly registered domains.
- Alert on crashes or memory corruption events in Flash Player binaries on endpoints.
- Track Flash Player version inventory to find hosts still below the fixed builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-0336 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-0336), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.