Vulnerability record · CVE-2015-5130 · published 14 August 2015
CVE-2015-5130: Adobe Flash Player use-after-free allows remote code execution
Opensuse · Evergreen
Adobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain a use-after-free flaw that lets attackers execute arbitrary code. The affected versions are Flash Player before 18.0.0.232 on Windows/OS X and before 11.2.202.508 on Linux, and AIR/SDK before 18.0.0.199. It matters because Flash was widely deployed and this class of bug gives full code execution in the context of the player.
Description
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5127, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550, CVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5559, CVE-2015-5561, CVE-2015-5563, CVE-2015-5564, and CVE-2015-5565.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 10.0 with network reachability, no authentication and public exploit code, though the product is legacy and the record lacks exploit-in-the-wild confirmation.
What it is
Adobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain a use-after-free flaw that lets attackers execute arbitrary code. The affected versions are Flash Player before 18.0.0.232 on Windows/OS X and before 11.2.202.508 on Linux, and AIR/SDK before 18.0.0.199. It matters because Flash was widely deployed and this class of bug gives full code execution in the context of the player.
Impact
An attacker can execute arbitrary code on the victim's machine, with the CVSS v2 vector indicating complete loss of confidentiality, integrity and availability. In practice this means host compromise, not just a crashed plugin.
Attack surface
The CVSS v2 vector AV:N/AC:L/Au:N means it is reachable over the network with no authentication and low complexity, consistent with a malicious SWF or web page loaded by the player. The description says only 'unspecified vectors', so the exact trigger is not documented; user interaction (opening the content) is implied but not stated.
Exploitation
Not listed in CISA KEV, but EPSS is 0.50286 (98.9th percentile) and an Exploit-DB entry (37854) exists, indicating public exploit code is available. No ransomware association is documented.
What to do
- Patch immediately to Flash Player 18.0.0.232 (Windows/OS X) or 11.2.202.508 (Linux), and AIR/AIR SDK 18.0.0.199 or later, per Adobe APSB15-19.
- Apply vendor updates for bundled distributions (Red Hat RHSA-2015-1603, openSUSE, Gentoo GLSA 201508-01, HPE advisories).
- Remove or disable Flash Player where it is no longer required; it is end-of-life and this is one of many similar flaws.
- Restrict browser plugin execution and block untrusted SWF content at the network or email gateway.
- If patching is not possible, isolate affected systems and limit browsing to trusted sites.
Detection
- Hunt for Flash Player versions below 18.0.0.232 (Windows/OS X) or 11.2.202.508 (Linux) across endpoints.
- Monitor for browser or plugin processes spawning unexpected child processes, a common post-exploitation signal for Flash RCE.
- Review proxy and IDS logs for SWF downloads from untrusted or newly registered domains.
- Check for the Exploit-DB 37854 sample or related SWF hashes in file and email scanning.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-5130 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-5130), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.