Vulnerability record · CVE-2015-7645 · published 15 October 2015
CVE-2015-7645: Adobe Flash Player SWF File Remote Code Execution
Adobe · Flash Player
Adobe Flash Player versions 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X, and 11.x through 11.2.202.535 on Linux, allow remote attackers to execute arbitrary code via a crafted SWF file. The flaw was exploited in the wild in October 2015, and the product is end-of-life, so any remaining installation is a serious exposure.
Description
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe vulnerability is in the CISA KEV catalog with known ransomware use, has a very high EPSS score, and affects an end-of-life product that should no longer be present.
What it is
Adobe Flash Player versions 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X, and 11.x through 11.2.202.535 on Linux, allow remote attackers to execute arbitrary code via a crafted SWF file. The flaw was exploited in the wild in October 2015, and the product is end-of-life, so any remaining installation is a serious exposure.
Impact
An attacker can execute arbitrary code in the context of the user running Flash Player, potentially leading to full system compromise. Because the product is end-of-life, successful exploitation can also enable follow-on ransomware deployment.
Attack surface
The vulnerability is reached when a user opens a crafted SWF file, typically delivered via a web page or document. The CVSS vector indicates local access with user interaction required and no privileges needed, meaning the victim must be induced to load the malicious content.
Exploitation
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2022-03-03, confirming in-the-wild exploitation, and EPSS shows a 30-day probability of 0.65578 (99.224th percentile). References include an Exploit-DB entry and a Trend Micro report describing its use in the Pawn Storm campaign.
What to do
- Apply the vendor patch referenced in Adobe security bulletin APSB15-27 or later Flash Player updates.
- Disconnect or remove Adobe Flash Player from all systems, as the product is end-of-life and no longer receives security fixes.
- If Flash cannot be removed immediately, disable or uninstall the Flash browser plug-in and block SWF content execution.
- Restrict user ability to open untrusted SWF files and enforce application allowlisting where feasible.
- Monitor for and block known exploit delivery vectors associated with the Pawn Storm campaign.
Detection
- Hunt for processes loading Flash Player (e.g., flash player plug-in or standalone) that subsequently spawn unusual child processes such as cmd.exe, powershell.exe, or scripting hosts.
- Monitor for SWF file downloads or executions from email, web, or removable media, especially files with unusual origins or embedded objects.
- Review endpoint logs for exploitation artifacts matching the IExternalizable.writeExternal type confusion described in public analyses.
- Correlate network indicators from the Trend Micro Pawn Storm report and Exploit-DB entry against proxy and IDS logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-7645 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Adobe Flash Player Arbitrary Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 24 March 2022.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-7645 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-7645), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.