Vulnerability record · CVE-2015-3090 · published 13 May 2015
CVE-2015-3090: Adobe Flash Player memory corruption allows arbitrary code execution
Adobe · Flash Player
Adobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain a memory corruption flaw (CWE-119) reachable via unspecified vectors. Successful exploitation lets an attacker execute arbitrary code or crash the affected process. The record does not describe the specific trigger, so the exact attack path is unknown.
Description
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3078, CVE-2015-3089, and CVE-2015-3093.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityNetwork-reachable, no authentication, full C/I/A impact and a very high EPSS score, though no confirmed in-the-wild exploitation is recorded.
What it is
Adobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain a memory corruption flaw (CWE-119) reachable via unspecified vectors. Successful exploitation lets an attacker execute arbitrary code or crash the affected process. The record does not describe the specific trigger, so the exact attack path is unknown.
Impact
An attacker can execute arbitrary code in the context of the affected product or cause a denial of service. Given the CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C, full confidentiality, integrity and availability impact is possible.
Attack surface
The CVSS vector is network-reachable with no authentication required and low complexity, consistent with a malicious SWF or web content loaded by the victim. The description does not state whether user interaction is required, but Flash content delivery typically involves a user opening a page or file.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation in this record. EPSS is very high (0.8318, 99.66th percentile), indicating strong predicted likelihood of exploitation activity.
What to do
- Apply the vendor patch: upgrade Flash Player to 13.0.0.289 or later, 17.0.0.188 or later, Linux 11.2.202.460 or later, and AIR/AIR SDK/AIR SDK & Compiler to 17.0.0.172 or later.
- Remove or disable Flash Player and AIR where they are not business-required, since the platform is end-of-life.
- Enforce browser settings that block or click-to-play Flash content and restrict untrusted SWF execution.
- Apply the referenced Linux distribution updates (SUSE, Red Hat, Gentoo) on hosts that still ship Flash.
- Segment or restrict systems that must retain Flash so they cannot reach untrusted web content.
Detection
- Monitor for Flash Player or AIR process crashes, which can indicate memory corruption attempts.
- Alert on SWF files or Flash content loaded from untrusted or newly seen domains.
- Hunt for unexpected child processes spawned by browser or Flash plugin processes.
- Review endpoint logs for exploitation artifacts around the affected Adobe product versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-3090 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-3090), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.