Vulnerability record · CVE-2015-5561 · published 14 August 2015
CVE-2015-5561: Adobe Flash Player use-after-free allows remote code execution
Adobe · Flash Player
Adobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain a use-after-free vulnerability that lets attackers execute arbitrary code. The flaw is one of a large batch of similar memory-corruption issues fixed in the same Adobe update, and it affects Windows, OS X and Linux builds. Because Flash content is widely embedded and the flaw is remotely reachable, it matters for any environment still running unpatched Flash or AIR.
Description
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5127, CVE-2015-5130, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550, CVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5559, CVE-2015-5563, CVE-2015-5564, and CVE-2015-5565.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote, unauthenticated code execution with a 10.0 CVSS 2.0 score and very high EPSS, though the product is legacy and no KEV listing or confirmed in-the-wild exploitation is recorded.
What it is
Adobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain a use-after-free vulnerability that lets attackers execute arbitrary code. The flaw is one of a large batch of similar memory-corruption issues fixed in the same Adobe update, and it affects Windows, OS X and Linux builds. Because Flash content is widely embedded and the flaw is remotely reachable, it matters for any environment still running unpatched Flash or AIR.
Impact
An attacker can execute arbitrary code in the context of the affected process, which for a browser plugin typically means the user's session and potentially full host compromise. The CVSS 2.0 vector rates complete confidentiality, integrity and availability impact.
Attack surface
The vector is AV:N/AC:L/Au:N, so it is network reachable with no authentication required. The description does not specify the exact delivery path, but Flash flaws of this class are normally reached by a victim loading crafted content, so some form of user interaction (opening a page or file) is likely.
Exploitation
Not listed in CISA KEV and no reference is tagged as exploit code, but EPSS is 0.44792 (98.7th percentile), indicating a high modeled probability of exploitation activity. No public exploit details are given in the record.
What to do
- Patch Flash Player to 18.0.0.232 or later on Windows and OS X, and 11.2.202.508 or later on Linux, per Adobe APSB15-19.
- Update Adobe AIR, AIR SDK and AIR SDK & Compiler to 18.0.0.199 or later.
- If Flash cannot be patched or removed, disable the plugin in browsers and block Flash content by default.
- Prioritize removal of Flash and AIR from endpoints, since the product line is end-of-life and no longer receives security fixes.
- Apply the referenced Red Hat, openSUSE and Gentoo advisories on Linux hosts to keep distribution packages current.
Detection
- Hunt for Flash Player or AIR versions below the fixed builds on endpoints and inventory any remaining installations.
- Monitor for browser or plugin process crashes followed by unexpected child process creation, a common pattern for use-after-free exploitation.
- Alert on Flash content (.swf) downloads or executions from untrusted or unusual sources.
- Review proxy and endpoint logs for known Flash exploit kit landing pages and payload delivery.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-5561 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-5561), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.