CVE-2015-7645 is a critical arbitrary code execution vulnerability affecting Adobe Flash Player versions 18.x through 18.0.0.252, 19.x through 19.0.0.207 on Windows and OS X, and 11.x through 11.2.202.535 on Linux, stemming from a type confusion flaw in IExternalizable.writeExternal. This vulnerability carries a high CVSS score of 7.8, indicating a severe impact with high confidentiality, integrity, and availability compromise. It is actively exploited in the wild, including in known ransomware campaigns, and has garnered significant community discussion and media coverage, with exploit code publicly available on ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 18.0.0.160, <= 18.0.0.252CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
19.0.0.185CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:19.0.0.185:*:*:*:*:*:*:* | ||
19.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:19.0.0.207:*:*:*:*:*:*:* | ||
<= 11.2.202.535CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
11.4CPE matchmatch criteria | cpe:2.3:o:opensuse:evergreen:11.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.