Use-after-free Vulnerability in Adobe Flash Player and Adobe AIR
CVE-2015-8646

8.8HIGH

Key Information:

Vendor
Adobe
Status
Vendor
CVE Published:
28 December 2015

Summary

The vulnerability allows attackers to exploit a use-after-free error in Adobe Flash Player and Adobe AIR, leading to the potential execution of arbitrary code. This flaw affects multiple versions of Adobe Flash Player across Windows, OS X, and Linux platforms, as well as Adobe AIR and its SDKs. The vulnerability arises from improper handling of memory, which can be manipulated by attackers to gain unauthorized access and control over affected systems.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.