CVE-2015-7648 is a critical type confusion vulnerability in Adobe Flash Player affecting versions before 18.0.0.255, 19.x before 19.0.0.226, and 11.2.202.540 on Linux, impacting Windows, OS X, and Linux systems. With a CVSS score of 10.0, it allows unauthenticated attackers to execute arbitrary code remotely with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability was actively exploited as a zero-day by groups like Pawn Storm and incorporated into exploit kits, garnering significant media and community attention, and exploit code is publicly available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.2.202.535CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 19.0.0.207CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.