CVE-2015-7647 is a critical type confusion vulnerability in Adobe Flash Player, affecting versions before 18.0.0.255, 19.x before 19.0.0.226 on Windows and OS X, and before 11.2.202.540 on Linux. This vulnerability allows unauthenticated attackers to execute arbitrary code remotely with low attack complexity. With a CVSS score of 10.0 and a FAUCET Risk Score of 98/100, its impact includes complete compromise of confidentiality, integrity, and availability. This zero-day vulnerability was actively exploited in the wild by groups like Pawn Storm, with exploit code publicly available on ExploitDB, and garnered significant media and community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.2.202.535CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 19.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.