LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2015-5122: Adobe Flash Player Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 13, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 4, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2015-5122 to its Known Exploited Vulnerabilities catalog on Apr 13, 2022, with a federal patch deadline of May 4, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

How it works

This issue is a use-after-free weakness (CWE-416) in Adobe Flash Player. In the DisplayObject class within the ActionScript 3 (AS3) implementation, memory that has already been freed can still be referenced. An attacker who can deliver crafted content that exercises this path may cause the player to use that stale memory, leading to arbitrary code execution or a denial-of-service condition. Public detail on exact trigger sequences is limited; treat any remote Flash content as a potential vector and confirm mechanics against the original vendor advisory.

Because Flash historically ran inside browsers and other host applications, successful abuse typically required the victim to load malicious SWF or embedded Flash content. The result is either full code execution in the context of the Flash process or a crash that disrupts availability.

Am I affected? How to find it in your systems

Adobe Flash Player is the affected product. It commonly appeared as a browser plugin, an embedded runtime in desktop applications, or a standalone player on endpoints and some legacy kiosks. Inventory every system that might still host Flash binaries or browser plugins.

How to remediate

The impacted product is end-of-life. CISA’s required action is to disconnect it if it is still in use. Remove Adobe Flash Player completely from all systems rather than attempting to patch. Uninstall via the operating-system package manager or Adobe’s removal tools, then verify that no plugin or runtime files remain.

After removal, validate with file-system and process inventory that the component is gone. Confirm any residual configuration guidance against the last vendor advisory for the product.

If you can't patch immediately

Immediate removal is the correct long-term control. Until that is finished, apply compensating measures that reduce exposure for this weakness class:

These steps only buy time; the definitive action remains full disconnection and removal of the end-of-life product.

If your data may have been exposed

Actively exploited vulnerabilities of this type have historically led to endpoint compromise and subsequent data theft. If Flash was present and untrusted content may have been loaded, assume possible code execution and perform standard incident response: isolate the host, collect volatile evidence, and hunt for persistence or lateral movement. Ransomware use specifically tied to this CVE is not documented, but any code-execution foothold warrants full investigation. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Flash Player
WeaknessCWE-416
Added to CISA KEVApr 13, 2022
Federal patch deadlineMay 4, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities