Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Flash Apsb15 27 | — | Upgrade to Adobe Flash Player version 19.0.0.226 for WindowsUpgrade to Adobe Flash Player version 18.0.0.255 for WindowsUpgrade to Adobe Flash Player version 18.0.0.255 for Mac OS XUpgrade to Adobe Flash Player version 19.0.0.226 for Mac OS XUpgrade to Adobe Flash Player version 11.2.202.540 for Linux | Oct 19, 2015 | Oct 15, 2015 |
| Freebsd | — | Upgrade linux-f10-flashpluginUpgrade linux-c6_64-flashpluginUpgrade linux-c6-flashplugin | Dec 10, 2025 | Oct 16, 2015 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Oct 15, 2015 |
| Suse | — | Upgrade flash-player-gnomeUpgrade flash-playerUpgrade flash-player-kde4 | Dec 18, 2015 | Oct 15, 2015 |
| Ubuntu | — | Upgrade flashplugin-nonfreeUpgrade adobe-flashplugin | Nov 19, 2024 | Oct 15, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub