CVE Tools

Description

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.

In plain language

AI Act now

CVE-2015-7645 is a Flash Player flaw that lets attackers run code when a user opens a specially made Flash (SWF) file; if you still have Flash Player installed and it can be reached by users, this is an urgent problem to remove or disable.

Executive summary

CVE-2015-7645 is a Flash Player code-execution vulnerability triggered by a crafted SWF that can be used in real-world campaigns (listed in CISA KEV and associated with ransomware); the affected Flash versions are end-of-life, so the practical fix is to disconnect/remove/disable Flash rather than rely on updates.

If affected, business impact
Ransomware attack entry pointFull device compromise riskService disruption from malwareData theft from compromised system

What to do now

  1. Check every Windows, macOS, and Linux machine where a browser or other app can use Adobe Flash Player, and record the installed Flash Player version.
  2. If you find Flash Player within: 18.x–18.0.0.252, 19.x–19.0.0.207, or 11.x–11.2.202.535, treat the machine as affected.
  3. Remove or disable Adobe Flash Player everywhere it’s installed (and disable Flash playback in any browser or app that might use it).
  4. If any affected machine is still in use for user browsing, disconnect it from the network until Flash is fully removed/disabled.
  5. Confirm users can no longer load Flash content (test a known Flash page or verify Flash is blocked in browser settings), then monitor for related suspicious activity.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:LAC:LPR:NUI:RS:UC:HI:HA:H
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 5 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Mar 3, 2022
Remediation due:Mar 24, 2022
Ransomware:Known ransomware use

Required action: The impacted product is end-of-life and should be disconnected if still in use.

2 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

References

and 12 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2015-7645 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows