CVE-2015-0313
Adobe Flash Player Use-After-Free Vulnerability
Description
CVE-2015-0313 is a use-after-free vulnerability in Adobe Flash Player that enables remote code execution through malicious Flash content delivered via web pages or online advertisements. The vulnerability was exploited as a zero-day through malvertising campaigns on major websites before a patch was available. CISA has added CVE-2015-0313 to the Known Exploited Vulnerabilities catalog. With an EPSS score of 97.2% (99.9th percentile), it is among the most exploited Flash Player vulnerabilities, representing a major threat during the Flash Player era.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| adobe | flash player | < 11.2.202.442; < 13.0.0.269; >= 14.0.0.125, < 16.0.0.305 |
| opensuse | evergreen | 11.4 |
| opensuse | opensuse | 13.1; 13.2 |
| suse | linux enterprise desktop | 11; 12 |
| suse | linux enterprise workstation extension | 12 |
| microsoft | internet explorer | 10; 11 |
| microsoft | edge | - |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00006.html(Mailing List, Third Party Advisory)
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00007.html(Mailing List, Third Party Advisory)
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00008.html(Mailing List, Third Party Advisory)
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00009.html(Mailing List, Third Party Advisory)
- http://packetstormsecurity.com/files/131189/Adobe-Flash-Player-ByteArray-With-Workers-Use-After-Free.html(Exploit, Third Party Advisory, VDB Entry)
- http://secunia.com/advisories/62528(Broken Link)
- http://secunia.com/advisories/62777(Broken Link)
- http://secunia.com/advisories/62895(Broken Link)
- http://www.osvdb.org/117853(Broken Link)
- http://www.securityfocus.com/bid/72429(Broken Link, Third Party Advisory, VDB Entry)
- http://www.securitytracker.com/id/1031686(Broken Link, Third Party Advisory, VDB Entry)
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100641(Third Party Advisory, VDB Entry)
- https://helpx.adobe.com/security/products/flash-player/apsa15-02.html(Vendor Advisory)
- https://helpx.adobe.com/security/products/flash-player/apsb15-04.html(Broken Link)
- https://technet.microsoft.com/library/security/2755801(Patch, Vendor Advisory)
- https://www.exploit-db.com/exploits/36579/(Exploit, Third Party Advisory, VDB Entry)
- https://github.com/cisagov/vulnrichment/issues/196(Issue Tracking)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-0313(US Government Resource)
Weakness Type
CWE-416: Use After Free
CWE-416 describes a weakness where software references memory after it has been freed, potentially leading to arbitrary code execution. In CVE-2015-0313, Adobe Flash Player contains a use-after-free condition that is triggered during processing of specially crafted SWF content, allowing an attacker to redirect execution to arbitrary code.
Learn more: CWE-416 — Use After Free
Impact Analysis
CVE-2015-0313 enables full remote code execution through the browser without any user interaction beyond visiting an affected web page. The vulnerability was exploited through malvertising networks, meaning legitimate major websites unknowingly served malicious Flash advertisements that compromised visitors. This attack vector gave the exploit unprecedented reach, as users were compromised simply by browsing popular websites. The confidentiality, integrity, and availability of affected systems were fully compromised, with attackers able to install malware, steal credentials, and establish persistent access.
Exploit Maturity
CVE-2015-0313 was exploited as a zero-day through malvertising campaigns targeting visitors of major websites including dailymotion.com. The EPSS score of 97.2% (99.9th percentile) confirms it as one of the most certain-to-be-exploited vulnerabilities. The Angler exploit kit was the primary vehicle for mass exploitation, and the malvertising delivery method enabled compromise of users on trusted, high-traffic websites without requiring direct interaction with attacker-controlled infrastructure.
Remediation
- Remove Adobe Flash Player entirely as required by CISA KEV — Flash Player reached end of life on December 31, 2020.
- Verify complete removal from all endpoints and disable any remaining Flash plugins in browsers.
- Block Flash content at the network perimeter and through browser security policies.
- For legacy applications requiring Flash, implement strict sandboxing and network isolation.
- Review advertising and content delivery configurations to block third-party Flash-based advertisements on managed websites.
Technical Details
CVE-2015-0313 is a use-after-free vulnerability in Adobe Flash Player that occurs during processing of SWF content. The vulnerability is triggered when the Flash Player frees a memory object during a specific sequence of ActionScript operations but subsequently accesses the freed memory through a retained reference. The attacker exploits this dangling pointer by arranging for the freed memory to be reallocated with attacker-controlled data, enabling heap corruption and code execution. The Angler exploit kit delivered the attack through Flash advertisements served by legitimate advertising networks, achieving drive-by compromise of website visitors.
Frequently Asked Questions
Is CVE-2015-0313 being actively exploited?
Yes. CVE-2015-0313 was exploited as a zero-day through malvertising campaigns on major websites. It is listed in the CISA KEV catalog with a 99.9th percentile EPSS score.
What products are affected by CVE-2015-0313?
CVE-2015-0313 affects Adobe Flash Player across all platforms. Flash Player is end-of-life and should be completely removed from all systems.
How do I fix CVE-2015-0313?
Remove Adobe Flash Player entirely from all systems. Block Flash content in browsers and at network perimeters.
How severe is CVE-2015-0313?
CVE-2015-0313 is a critical use-after-free vulnerability that was exploited through malvertising on major websites, enabling mass compromise of users without any required interaction. Its 99.9th percentile EPSS score confirms it as one of the most exploited Flash vulnerabilities.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.