Vulnerability record · CVE-2015-8651 · published 28 December 2015
CVE-2015-8651: Adobe Flash Player Integer Overflow Allows Remote Code Execution
Adobe · Air Sdk
Adobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain an integer overflow (CWE-190) that allows attackers to execute arbitrary code via unspecified vectors. The flaw affects Flash Player before 18.0.0.324 and 19.x/20.x before 20.0.0.267 on Windows and OS X, and before 11.2.202.559 on Linux, plus AIR before 20.0.0.233. It matters because Flash was widely deployed and the flaw yields full code execution in the context of the user.
Description
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw gives remote code execution, is listed in CISA KEV as exploited, and carries a very high EPSS score, while the affected product is end-of-life and may remain in use.
What it is
Adobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain an integer overflow (CWE-190) that allows attackers to execute arbitrary code via unspecified vectors. The flaw affects Flash Player before 18.0.0.324 and 19.x/20.x before 20.0.0.267 on Windows and OS X, and before 11.2.202.559 on Linux, plus AIR before 20.0.0.233. It matters because Flash was widely deployed and the flaw yields full code execution in the context of the user.
Impact
An attacker who successfully triggers the overflow can execute arbitrary code with the privileges of the affected process, giving high confidentiality, integrity and availability impact. No privilege escalation beyond the running user is described.
Attack surface
The CVSS vector is network-reachable with user interaction required (AV:N/AC:L/PR:N/UI:R), consistent with a victim opening a crafted Flash or AIR content file or visiting a malicious page. No authentication is needed; the attacker relies on the user to load the malicious content.
Exploitation
CVE-2015-8651 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-25), and EPSS gives a 30-day exploitation probability of roughly 0.68 (99.3rd percentile). No ransomware campaign use is documented in the record.
What to do
- Apply the vendor fix: upgrade Flash Player to 18.0.0.324 or later (or 20.0.0.267 for 19.x/20.x on Windows/OS X, 11.2.202.559 on Linux) and AIR/AIR SDK to 20.0.0.233 or later.
- Because Flash Player is end-of-life, remove or disconnect it wherever it is still installed, per CISA's required action.
- Disable or block Flash content in browsers and email clients, and prevent automatic execution of Flash/AIR files.
- Apply the referenced Linux distribution and vendor advisories (Red Hat, SUSE/openSUSE, Gentoo, HP) for bundled or dependent packages.
- Restrict user ability to open untrusted SWF/AIR content and monitor for legacy Flash usage on endpoints.
Detection
- Hunt for Flash Player or AIR processes spawning child processes such as cmd.exe, powershell.exe or /bin/sh, which is abnormal for normal playback.
- Monitor for SWF or AIR file downloads and execution from email attachments, web downloads or temporary directories.
- Alert on Flash Player versions below the fixed builds (18.0.0.324, 20.0.0.267, 11.2.202.559) via software inventory.
- Review proxy and DNS logs for known exploit-kit or malicious Flash hosting patterns, and correlate with endpoint process creation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-8651 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Adobe Flash Player Integer Overflow Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 15 June 2022.
Affected products
17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-8651 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-8651), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.