Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-3043

97
FAUCET Score

CVE-2015-3043 is a critical memory corruption vulnerability in Adobe Flash Player, affecting versions before 13.0.0.281, 14.x through 17.x before 17.0.0.169 on Windows and OS X, and before 11.2.202.457 on Linux. This flaw allows attackers to execute arbitrary code or cause a denial of service. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. The vulnerability has been actively exploited in the wild since April 2015, with publicly available exploit code, including a Metasploit module, and significant community discussion and media coverage highlighting its widespread impact and use by advanced persistent threat (APT) groups.

Impacted Technologies

VendorProductVersion(s)CPE
< 11.2.202.457CPE matchmatch criteria
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
< 13.0.0.281CPE matchmatch criteria
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
>= 14.0.0.125, < 17.0.0.169CPE matchmatch criteria
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
11.0CPE matchmatch criteria
cpe:2.3:o:novell:suse_linux_enterprise_desktop:11.0:sp3:*:*:*:*:*:*
12.0CPE matchmatch criteria
cpe:2.3:o:novell:suse_linux_enterprise_desktop:12.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
79.83%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Added to KEV · Mar 3, 2022
Metasploit: Adobe Flash Player Nellymoser Audio Decoding Buffer Overflow · Jun 23, 2015
ExploitDB: EDB-37536 · Jul 8, 2015
This CVE's current EPSS score of 0.7983 is in the 98th percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

adobepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5 SupplementaryFixed in: flash-plugin-0:11.2.202.457-1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: flash-plugin-0:11.2.202.457-1.el6_6
View patch

Vendor Advisories (1)

redhatCVE-2015-3043Critical

flash-plugin: multiple code execution issues fixed in APSB15-06

Apr 14, 2015

References

github.com / cisagov/vulnrichment/issues/196
Issue Tracking
cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
lists.opensuse.org / opensuse-security-announce/2015-04/msg00010.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-04/msg00011.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-04/msg00012.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-04/msg00013.html
Mailing ListThird Party Advisory
rhn.redhat.com / errata/RHSA-2015-0813.html
Third Party Advisory
helpx.adobe.com / security/products/flash-player/apsb15-06.html
Broken LinkPatchVendor Advisory
security.gentoo.org / glsa/201504-07
Third Party Advisory
exploit-db.com / exploits/37536
ExploitThird Party AdvisoryVDB Entry
securityfocus.com / bid/74062
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1032105
Broken LinkThird Party AdvisoryVDB Entry