CVE-2015-0313
critical-risk
Published 2015-02-02
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
Do I need to act?
!
92.8% chance of exploitation in next 30 days
EPSS score — higher than 7% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (10)
References (34)
Broken Link
http://secunia.com/advisories/62528
Broken Link
http://secunia.com/advisories/62777
Broken Link
http://secunia.com/advisories/62895
Broken Link
http://www.osvdb.org/117853
Broken Link
http://www.securityfocus.com/bid/72429
Broken Link
http://www.securitytracker.com/id/1031686
Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/100641
and 14 more references
82
/ 100
critical-risk
Severity
32/34 · Critical
Exploitability
34/34 · Critical
Exposure
16/34 · Moderate