LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2015-5119: Adobe Flash Player Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2015-5119 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.

CVE-2015-5119 is a use-after-free vulnerability in Adobe Flash Player that can allow an attacker to achieve remote code execution. It matters because Flash content was historically embedded in browsers and documents; a successful exploit could let an attacker run code in the context of the user who opened the malicious content. The product is end-of-life, so any remaining installations represent ongoing risk that should be removed rather than maintained.

Public detail is limited to the class of flaw and the affected component. Confirm exact impact, fixed builds (if any were issued at the time), and deployment guidance against the original vendor advisory and your own inventory.

How it works

The weakness is recorded as CWE-119 and is described as a use-after-free condition inside the ActionScript 3 ByteArray class in Adobe Flash Player. In a use-after-free flaw, the application frees a block of memory but later continues to use a reference to that memory. An attacker who can influence the allocation and reuse of that memory may corrupt program state.

According to the CISA summary, this can be abused to perform remote code execution. In practice for this product class, that typically means the victim must process attacker-controlled Flash content (for example via a web page or embedded object). Specific exploit mechanics, heap-spray techniques, or payload details are not provided here and should not be assumed; treat any untrusted Flash content as potentially dangerous and verify behavior only in isolated analysis environments.

Am I affected? How to find it in your systems

Adobe Flash Player historically ran as a browser plug-in, an ActiveX control, or a standalone projector on Windows, macOS, and other desktops, and was sometimes bundled with enterprise software or kiosks. Because the product is end-of-life, the primary question is whether any instance still exists at all.

How to remediate

The CISA required action is clear: the impacted product is end-of-life and should be disconnected if still in use. Removal is the definitive remediation.

If you can't patch immediately

When immediate uninstall is blocked by a legacy dependency, reduce exposure until the dependency can be retired.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities can lead to endpoint compromise, credential theft, and follow-on data exposure. Known ransomware use is not documented for this CVE in the provided facts; still, treat confirmed exploitation as a security incident and follow your normal containment, forensics, and notification procedures. If you believe accounts or systems were affected, review access logs, rotate credentials, and check whether sensitive data left the environment. You can run a free exposure scan of your email addresses against known breach data sets to see whether those identities have appeared in prior documented breaches, then take appropriate account-hardening steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Flash Player
WeaknessCWE-119
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities