CVE-2015-7645
Description
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.
In plain language
AI Act nowCVE-2015-7645 is a Flash Player flaw that lets attackers run code when a user opens a specially made Flash (SWF) file; if you still have Flash Player installed and it can be reached by users, this is an urgent problem to remove or disable.
CVE-2015-7645 is a Flash Player code-execution vulnerability triggered by a crafted SWF that can be used in real-world campaigns (listed in CISA KEV and associated with ransomware); the affected Flash versions are end-of-life, so the practical fix is to disconnect/remove/disable Flash rather than rely on updates.
What to do now
- Check every Windows, macOS, and Linux machine where a browser or other app can use Adobe Flash Player, and record the installed Flash Player version.
- If you find Flash Player within: 18.x–18.0.0.252, 19.x–19.0.0.207, or 11.x–11.2.202.535, treat the machine as affected.
- Remove or disable Adobe Flash Player everywhere it’s installed (and disable Flash playback in any browser or app that might use it).
- If any affected machine is still in use for user browsing, disconnect it from the network until Flash is fully removed/disabled.
- Confirm users can no longer load Flash content (test a known Flash page or verify Flash is blocked in browser settings), then monitor for related suspicious activity.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: The impacted product is end-of-life and should be disconnected if still in use.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2015-7645 and every CVE in our database. Create a free account — no credit card required.
Create Free Account