CVE-2015-0311: Adobe Flash Player Remote Code Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-04-13. EPSS: 85.6% chance of exploitation in the next 30 days.

Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.

Affected products

  • Adobe Flash Player: up to and including 11.2.202.438; up to and including 13.0.0.262; from 14.0.0.125, before 16.0.0.287 (fixed in 16.0.0.287)
  • Microsoft Edge: affected versions not specified
  • Microsoft Internet Explorer: version 10 only; version 11 only
  • Suse Linux Enterprise Desktop: version 11 only; version 12 only
  • Suse Linux Enterprise Workstation Extension: version 12 only

Published 2015-01-23. Last modified 2026-06-17.