CISA Known Exploited Vulnerability

CVE-2015-5122

Adobe · Flash Player

Adobe Flash Player Use-After-Free Vulnerability

Date added
BOD 22-01 due date
CWE CWE-416
Ransomware Unknown

CISA description

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

Required action

The impacted product is end-of-life and should be disconnected if still in use.