Vulnerability record · CVE-2015-5119 · published 8 July 2015
CVE-2015-5119: Adobe Flash Player ActionScript 3 ByteArray use-after-free
Adobe · Flash Player
A use-after-free flaw exists in the ByteArray class of the ActionScript 3 implementation in Adobe Flash Player. Crafted Flash content that overrides a valueOf function can corrupt memory, allowing remote code execution or a denial of service. The affected product is end-of-life, so any remaining deployment carries full risk.
Description
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, confirmed in-the-wild exploitation, CISA KEV listing and near-maximum EPSS make this a top-priority vulnerability for any system still running Flash Player.
What it is
A use-after-free flaw exists in the ByteArray class of the ActionScript 3 implementation in Adobe Flash Player. Crafted Flash content that overrides a valueOf function can corrupt memory, allowing remote code execution or a denial of service. The affected product is end-of-life, so any remaining deployment carries full risk.
Impact
An attacker can execute arbitrary code in the context of the Flash Player process or crash it, giving code execution on the victim host. Successful exploitation can lead to full compromise of the user's system.
Attack surface
Reached remotely over the network by delivering crafted Flash content to a browser or application hosting Flash Player; no authentication or user privileges are required, though the victim must load the malicious content. The CVSS vector shows network access, low complexity, no privileges and no user interaction.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-03-03, and the description states it was exploited in the wild in July 2015. EPSS is 0.99344 (99.9th percentile), and references include an exploit module and a public exploit write-up.
What to do
- Patch or remove Flash Player immediately; Adobe Flash Player is end-of-life and CISA's required action is to disconnect the product if still in use.
- If Flash cannot be removed, disable or block Flash content in browsers and applications via enterprise policy.
- Apply vendor updates for any bundled Flash components on Red Hat, openSUSE and SUSE Linux distributions.
- Restrict network access to untrusted Flash content and block known malicious domains and exploit delivery paths.
- Retire or isolate systems that still depend on Flash Player.
Detection
- Monitor for Flash Player process crashes and memory corruption events, especially from browser plugins.
- Hunt for known exploit artifacts and payloads associated with the ByteArray valueOf use-after-free, including the public exploit module.
- Review proxy and network logs for delivery of crafted SWF content or known exploit hosts.
- Check endpoint telemetry for suspicious child processes spawned by browsers or Flash Player.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-5119 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Adobe Flash Player Use-After-Free Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 24 March 2022.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-5119 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-5119), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.