Vulnerability record · CVE-2015-3043 · published 14 April 2015
CVE-2015-3043: Adobe Flash Player memory corruption allows arbitrary code execution
Adobe · Flash Player
Adobe Flash Player contains an out-of-bounds write (CWE-787) that corrupts memory and can lead to arbitrary code execution or a denial of service. The flaw affects Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X, and before 11.2.202.457 on Linux. It was exploited in the wild in April 2015, and the affected product is end-of-life.
Description
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 3.1 score is 9.8, the flaw is confirmed exploited in the wild, it is in CISA KEV, and EPSS is above the 99th percentile.
What it is
Adobe Flash Player contains an out-of-bounds write (CWE-787) that corrupts memory and can lead to arbitrary code execution or a denial of service. The flaw affects Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X, and before 11.2.202.457 on Linux. It was exploited in the wild in April 2015, and the affected product is end-of-life.
Impact
An attacker can execute arbitrary code in the context of the Flash Player process or crash it, giving full control of confidentiality, integrity and availability on the victim host. No privileges are required and no user interaction is needed per the CVSS vector.
Attack surface
Reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N) per the CVSS 3.1 vector; in practice this means malicious Flash content delivered to a host running a vulnerable player. The description does not specify the exact delivery vector beyond unspecified vectors.
Exploitation
Exploitation is confirmed: the record states it was exploited in the wild in April 2015, CISA KEV lists it with a 2022-03-24 remediation due date, and an Exploit-DB entry is referenced. EPSS is 0.73862 (99.45th percentile), indicating high predicted exploitation activity.
What to do
- Patch or remove Flash Player: upgrade to 13.0.0.281 or later, 17.0.0.169 or later on Windows/OS X, or 11.2.202.457 or later on Linux, per Adobe APSB15-06.
- Because Flash Player is end-of-life, disconnect or uninstall it wherever it is still in use, as CISA KEV requires.
- Apply the referenced vendor updates for Red Hat, openSUSE, SUSE and Gentoo packages that bundle Flash Player.
- Block or disable Flash content in browsers and email clients to prevent delivery of malicious SWF files.
- Restrict outbound and inbound network access for hosts that cannot remove Flash, and monitor for Flash process crashes.
Detection
- Hunt for Flash Player versions below the fixed thresholds (13.0.0.281, 17.0.0.169, 11.2.202.457) across endpoints.
- Monitor for unexpected crashes or abnormal termination of Flash Player processes (flash player plugin/browser processes).
- Review proxy and network logs for SWF downloads from untrusted or newly seen domains.
- Check for the Exploit-DB 37536 proof-of-concept artifacts or related indicators in endpoint telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-3043 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Adobe Flash Player Memory Corruption Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 24 March 2022.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-3043 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-3043), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.