CVE-2015-0311: Adobe Flash Player Remote Code Execution Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-04-13. EPSS: 85.6% chance of exploitation in the next 30 days.
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.
Affected products
- Adobe Flash Player: up to and including 11.2.202.438; up to and including 13.0.0.262; from 14.0.0.125, before 16.0.0.287 (fixed in 16.0.0.287)
- Microsoft Edge: affected versions not specified
- Microsoft Internet Explorer: version 10 only; version 11 only
- Suse Linux Enterprise Desktop: version 11 only; version 12 only
- Suse Linux Enterprise Workstation Extension: version 12 only
Published 2015-01-23. Last modified 2026-06-17.