← Vulnerability feed

Vulnerability record · CVE-2015-8651 · published 28 December 2015

CVE-2015-8651: Adobe Flash Player Integer Overflow Allows Remote Code Execution

Adobe · Air Sdk

Adobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain an integer overflow (CWE-190) that allows attackers to execute arbitrary code via unspecified vectors. The flaw affects Flash Player before 18.0.0.324 and 19.x/20.x before 20.0.0.267 on Windows and OS X, and before 11.2.202.559 on Linux, plus AIR before 20.0.0.233. It matters because Flash was widely deployed and the flaw yields full code execution in the context of the user.

8.8 CVSS 3.1 High CISA KEV since 25 May 2022 EPSS 68% · top 0.7% CWE-190 · Integer overflow
8.8CVSS 3.1 base score, v2 9.3
68%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
17Affected product versions listed by NVD
25References
17 Jun 2026Last modified by NVD

Description

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw gives remote code execution, is listed in CISA KEV as exploited, and carries a very high EPSS score, while the affected product is end-of-life and may remain in use.

What it is

Adobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain an integer overflow (CWE-190) that allows attackers to execute arbitrary code via unspecified vectors. The flaw affects Flash Player before 18.0.0.324 and 19.x/20.x before 20.0.0.267 on Windows and OS X, and before 11.2.202.559 on Linux, plus AIR before 20.0.0.233. It matters because Flash was widely deployed and the flaw yields full code execution in the context of the user.

Impact

An attacker who successfully triggers the overflow can execute arbitrary code with the privileges of the affected process, giving high confidentiality, integrity and availability impact. No privilege escalation beyond the running user is described.

Attack surface

The CVSS vector is network-reachable with user interaction required (AV:N/AC:L/PR:N/UI:R), consistent with a victim opening a crafted Flash or AIR content file or visiting a malicious page. No authentication is needed; the attacker relies on the user to load the malicious content.

Exploitation

CVE-2015-8651 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-25), and EPSS gives a 30-day exploitation probability of roughly 0.68 (99.3rd percentile). No ransomware campaign use is documented in the record.

What to do

  • Apply the vendor fix: upgrade Flash Player to 18.0.0.324 or later (or 20.0.0.267 for 19.x/20.x on Windows/OS X, 11.2.202.559 on Linux) and AIR/AIR SDK to 20.0.0.233 or later.
  • Because Flash Player is end-of-life, remove or disconnect it wherever it is still installed, per CISA's required action.
  • Disable or block Flash content in browsers and email clients, and prevent automatic execution of Flash/AIR files.
  • Apply the referenced Linux distribution and vendor advisories (Red Hat, SUSE/openSUSE, Gentoo, HP) for bundled or dependent packages.
  • Restrict user ability to open untrusted SWF/AIR content and monitor for legacy Flash usage on endpoints.

Detection

  • Hunt for Flash Player or AIR processes spawning child processes such as cmd.exe, powershell.exe or /bin/sh, which is abnormal for normal playback.
  • Monitor for SWF or AIR file downloads and execution from email attachments, web downloads or temporary directories.
  • Alert on Flash Player versions below the fixed builds (18.0.0.324, 20.0.0.267, 11.2.202.559) via software inventory.
  • Review proxy and DNS logs for known exploit-kit or malicious Flash hosting patterns, and correlate with endpoint process creation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2015-8651 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Adobe Flash Player Integer Overflow Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 15 June 2022.

Affected products

17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00045.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00046.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00047.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00048.html Mailing ListThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2697.html Third Party Advisory
http://www.securityfocus.com/bid/79705 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1034544 Broken LinkThird Party AdvisoryVDB Entry
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 Third Party Advisory
https://helpx.adobe.com/security/products/flash-player/apsb16-01.html Not ApplicablePatchVendor Advisory
https://security.gentoo.org/glsa/201601-03 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00045.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00046.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00047.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00048.html Mailing ListThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2697.html Third Party Advisory
http://www.securityfocus.com/bid/79705 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1034544 Broken LinkThird Party AdvisoryVDB Entry
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 Third Party Advisory
https://helpx.adobe.com/security/products/flash-player/apsb16-01.html Not ApplicablePatchVendor Advisory
https://security.gentoo.org/glsa/201601-03 Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-8651 US Government Resource

Track CVE-2015-8651 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-1019Adobe Flash Player memory corruption allows code executionAdobe Flash Player 21.0.0.197 and earlier contains an unspecified memory corruption flaw that can crash the application or allow arbitrary code execu…KEVEPSS 22%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed9.8CVE-2015-5122Adobe Flash Player ActionScript 3 Use-After-Free in DisplayObjectA use-after-free flaw in the DisplayObject class of Adobe Flash Player's ActionScript 3 implementation is triggered by crafted Flash content that mis…KEVEPSS 94%analysed9.8CVE-2015-5119Adobe Flash Player ActionScript 3 ByteArray use-after-freeA use-after-free flaw exists in the ByteArray class of the ActionScript 3 implementation in Adobe Flash Player. Crafted Flash content that overrides …KEVEPSS 99%analysed9.8CVE-2015-3113Adobe Flash Player heap buffer overflow allows remote code executionAdobe Flash Player contains a heap-based buffer overflow (CWE-122/CWE-787) reachable through unspecified vectors. It affects Flash Player before 13.0…KEVEPSS 100%analysed9.8CVE-2015-3043Adobe Flash Player memory corruption allows arbitrary code executionAdobe Flash Player contains an out-of-bounds write (CWE-787) that corrupts memory and can lead to arbitrary code execution or a denial of service. Th…KEVEPSS 74%analysed

Source: NIST National Vulnerability Database (record CVE-2015-8651), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.