Use-After-Free Vulnerability in Adobe Flash Player and Adobe AIR Products
CVE-2015-8641

8.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
28 December 2015

Summary

This vulnerability in Adobe Flash Player prior to version 18.0.0.324, and in specific versions of Adobe AIR, can be exploited by attackers to execute arbitrary code on affected systems. The flaw arises from improper handling of memory, specifically in how the software manages memory allocation, allowing an attacker to manipulate program execution. This can lead to significant security risks, including unauthorized access and system compromise.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.