CVE-2015-0311

CRITICAL(9.8)KEVLikely Exploited

Adobe Flash Player Remote Code Execution Vulnerability

Description

CVE-2015-0311 is a use-after-free vulnerability in Adobe Flash Player that allows remote code execution through malicious SWF content. The vulnerability was exploited as a zero-day by the Angler exploit kit, delivering drive-by download attacks through compromised web pages. CISA has added CVE-2015-0311 to the Known Exploited Vulnerabilities catalog. With an EPSS score of 97.4% (99.9th percentile), this is one of the most exploited Flash Player vulnerabilities, having powered widespread drive-by download campaigns during its active exploitation window.

KEV Information

Vendor
Adobe
Product
Flash Player
Date Added
April 13, 2022
Due Date
May 4, 2022
Required Action
The impacted product is end-of-life and should be disconnected if still in use.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

Affected Products

VendorProductVersion
adobeflash player<= 11.2.202.438; <= 13.0.0.262; >= 14.0.0.125, < 16.0.0.287
suselinux enterprise desktop11; 12
suselinux enterprise workstation extension12
microsoftinternet explorer10; 11
microsoftedge-

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-416: Use After Free

CWE-416 describes a weakness where software references memory after it has been freed, which can result in program crashes or arbitrary code execution. In CVE-2015-0311, Adobe Flash Player accesses freed memory during processing of crafted SWF content, enabling an attacker to control the freed memory contents and redirect program execution.

Learn more: CWE-416 — Use After Free

Impact Analysis

CVE-2015-0311 provides full remote code execution through the browser, with exploitation requiring only that a victim views a web page containing malicious Flash content. The vulnerability was used in drive-by download campaigns that required zero user interaction, making it an extremely effective mass exploitation tool. All aspects of system security are compromised upon successful exploitation — confidentiality through data theft, integrity through malware installation, and availability through ransomware or destructive payloads. The Angler exploit kit's use of this vulnerability for large-scale distribution of banking trojans and ransomware caused significant financial damage.

Exploit Maturity

CVE-2015-0311 was exploited as a zero-day by the Angler exploit kit before Adobe released a patch. The EPSS score of 97.4% (99.9th percentile) places it among the most exploited software vulnerabilities globally. The Angler exploit kit used this vulnerability as a primary payload delivery mechanism, serving malicious Flash content through compromised websites and malvertising networks to achieve mass infection rates. The vulnerability remained a top exploit kit payload even after patching due to slow patch adoption.

Remediation

  1. Remove Adobe Flash Player entirely as required by CISA KEV — Flash Player is end-of-life since December 31, 2020.
  2. Verify complete removal from all endpoints and server systems.
  3. Block Flash content at network perimeters, proxy servers, and in browser configurations.
  4. For legacy Flash dependencies, use application virtualization with strict network isolation.
  5. Review systems for residual malware from historical exploitation campaigns.

Technical Details

CVE-2015-0311 is a use-after-free vulnerability in Adobe Flash Player that occurs during processing of specially crafted SWF files. The Flash Player runtime frees a memory allocation during a specific ActionScript execution path but retains a reference to the freed memory. When the dangling reference is subsequently dereferenced, the attacker can control the contents at that memory location through heap manipulation techniques, redirecting execution to shellcode. The Angler exploit kit exploited this vulnerability through obfuscated SWF files embedded in web pages, using heap spray and return-oriented programming (ROP) techniques to achieve reliable code execution across multiple Flash Player versions.

Frequently Asked Questions

Is CVE-2015-0311 being actively exploited?

Yes. CVE-2015-0311 was exploited as a zero-day by the Angler exploit kit for drive-by download campaigns. It is listed in the CISA KEV catalog with a 99.9th percentile EPSS score.

What products are affected by CVE-2015-0311?

CVE-2015-0311 affects Adobe Flash Player across all platforms. Flash Player is end-of-life and should be completely removed.

How do I fix CVE-2015-0311?

Remove Adobe Flash Player entirely from all systems. Block Flash content in browsers and at network perimeters.

How severe is CVE-2015-0311?

CVE-2015-0311 is a critical use-after-free vulnerability that powered mass drive-by download campaigns through the Angler exploit kit. Its 99.9th percentile EPSS score confirms it as one of the most exploited Flash Player vulnerabilities.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score85.82%
EPSS Percentile99.7%

Dates

PublishedJanuary 23, 2015
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.