Vulnerability record · CVE-2015-3088 · published 13 May 2015
CVE-2015-3088: Adobe Flash Player Heap Buffer Overflow Allows Code Execution
Adobe · Flash Player
Adobe Flash Player, AIR, AIR SDK, and AIR SDK & Compiler contain a heap-based buffer overflow (CWE-119) reachable through unspecified vectors. Successful exploitation allows arbitrary code execution in the context of the affected process. The flaw affects Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X, before 11.2.202.460 on Linux, and AIR/AIR SDK/AIR SDK & Compiler before 17.0.0.172.
Description
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10.0, high EPSS percentile, and a public exploit make this a critical risk for any system still running vulnerable Flash Player or AIR versions.
What it is
Adobe Flash Player, AIR, AIR SDK, and AIR SDK & Compiler contain a heap-based buffer overflow (CWE-119) reachable through unspecified vectors. Successful exploitation allows arbitrary code execution in the context of the affected process. The flaw affects Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X, before 11.2.202.460 on Linux, and AIR/AIR SDK/AIR SDK & Compiler before 17.0.0.172.
Impact
An attacker can execute arbitrary code on the victim's system, potentially leading to full compromise of the affected host. Given the CVSS 2.0 score of 10.0 (complete confidentiality, integrity, and availability impact), the consequences are severe.
Attack surface
The vulnerability is network-reachable (AV:N) with low complexity (AC:L) and requires no authentication (Au:N). Exploitation likely occurs when a user views a malicious SWF file or visits a crafted web page, though the description does not specify the exact vector.
Exploitation
The CVE is not listed in CISA KEV, but EPSS indicates a 30-day exploitation probability of 0.61978 (99.138th percentile), and a public exploit exists on Exploit-DB (ID 37844). These factors suggest active exploitation is likely.
What to do
- Update Adobe Flash Player to version 13.0.0.289 or later on Windows and OS X, and to 11.2.202.460 or later on Linux.
- Update Adobe AIR, AIR SDK, and AIR SDK & Compiler to version 17.0.0.172 or later.
- Apply vendor patches referenced in Adobe security bulletin APSB15-09 and any relevant Linux distribution advisories (e.g., Red Hat, openSUSE, Gentoo).
- If Flash Player is not required, disable or uninstall it to eliminate the attack surface.
- Restrict browser plug-in execution and enforce click-to-play for Flash content where feasible.
Detection
- Monitor for network requests to known malicious SWF files or domains associated with exploit kits.
- Inspect endpoint logs for unexpected process creation or memory corruption indicators originating from Flash Player or AIR processes.
- Use YARA or similar rules to detect known exploit payloads targeting CVE-2015-3088 in memory or on disk.
- Track Flash Player version inventory to identify unpatched systems that remain vulnerable.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-3088 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-3088), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.