[CVE-2015-5123] Adobe Flash Player Use-After-Free Vulnerability

SecurityDesk
2022.04.13 00:00 조회 11

CISA KEV 정보

취약점명Adobe Flash Player Use-After-Free Vulnerability
설명Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
조치사항The impacted product is end-of-life and should be disconnected if still in use.
랜섬웨어 캠페인 악용Unknown
CWECWE-416
등록일 (KEV)2022-04-13
조치 기한2022-05-04
추가 참고https://nvd.nist.gov/vuln/detail/CVE-2015-5123

NVD 상세 정보

CVSS v3.1: 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0: 10.0 AV:N/AC:L/Au:N/C:C/I:C/A:C

설명: Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

CWE: CWE-416 | CWE-416

참조

This product uses the NVD API but is not endorsed or certified by the NVD.



바로 가기

IT 도구 서랍

→ Unix: 2025-01-15T09:30:00
→ 날짜: 1736934600

→ ASCII: ABC
→ 문자: 65 66 67

ASCII 코드표 — 클릭하면 입력란에 추가

DecHex약어설명
DecHex문자
DecHex문자

→ 유니코드: 홍길동
→ 문자: \ud64d\uae38\ub3d9