Vulnerability record · CVE-2015-0359 · published 14 April 2015
CVE-2015-0359: Adobe Flash Player double free allows arbitrary code execution
Adobe · Flash Player
Adobe Flash Player contains a double free vulnerability in versions before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X, and before 11.2.202.457 on Linux. Successful exploitation allows arbitrary code execution in the context of the affected process. The record does not specify the exact vectors beyond 'unspecified vectors'.
Description
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0346.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 and high EPSS probability indicate a severe, remotely exploitable flaw with complete impact, despite lack of KEV listing.
What it is
Adobe Flash Player contains a double free vulnerability in versions before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X, and before 11.2.202.457 on Linux. Successful exploitation allows arbitrary code execution in the context of the affected process. The record does not specify the exact vectors beyond 'unspecified vectors'.
Impact
An attacker can execute arbitrary code on the victim's system, potentially leading to full compromise of the user's machine. Given the CVSS 2.0 score of 10, the impact is complete loss of confidentiality, integrity, and availability.
Attack surface
The vulnerability is network-reachable (AV:N) with low complexity and no authentication required (Au:N), meaning an attacker can trigger it remotely, likely by enticing a user to visit a malicious web page or open a crafted Flash file. User interaction is not explicitly stated in the vector but is typically required for Flash content delivery.
Exploitation
The CVE is not listed in CISA KEV, but EPSS indicates a high probability of exploitation (0.92109, 99.8th percentile). No public exploit references are tagged in the record, so active exploitation status is unknown.
What to do
- Apply the vendor patch by upgrading to Adobe Flash Player 13.0.0.281 or later, 17.0.0.169 or later for 14.x-17.x, or 11.2.202.457 or later on Linux.
- Disable or uninstall Adobe Flash Player if it is not required for business operations.
- Configure browsers to require click-to-play for Flash content to reduce automatic execution.
- Apply the referenced Linux distribution updates (openSUSE, Red Hat, Gentoo) if using packaged Flash.
- Monitor for and block known malicious Flash content at the network perimeter.
Detection
- Monitor for crashes or abnormal process terminations in Flash Player that may indicate double-free exploitation attempts.
- Use endpoint detection to flag suspicious child processes spawned by browser or Flash Player processes.
- Inspect network traffic for Flash files (.swf) from untrusted sources and correlate with exploit attempts.
- Review system logs for signs of memory corruption or code execution in the context of Flash Player.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-0359 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-0359), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.