Adobe Flash Player use-after-free under active exploitation
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
CVE-2015-0313, a use-after-free in Adobe Flash Player, is actively exploited via malicious ads on high-traffic sites; patch to version 16.0.0.305 immediately.
The CERT-FR alerts to active exploitation of CVE-2015-0313, a use-after-free vulnerability in Adobe Flash Player affecting versions 16.0.0.296 and earlier on Windows/macOS and 13.x before 13.0.0.264 on Linux. The flaw exists in the FlashCC memory-access acceleration feature, where a freed ByteArray object leaves a dangling pointer in the ApplicationDomain's domainMemory field. An attacker sprays the heap with Vector objects, then uses domainMemory to read and write arbitrary process memory, enabling remote code execution within the Flash sandbox. The vulnerability has been exploited in the wild via compromised ad networks serving malicious content on sites including Dailymotion, Huffington Post, and Answers.com. Exploitation observed on Windows across all versions including 8.1. Adobe released patch 16.0.0.305 on 4 February 2015 and auto-deployed it to users with automatic updates enabled. The bulletin also addresses SSDP reflection attacks enabling DDoS amplification and recommends disabling UPnP services or restricting SSDP traffic at network boundaries.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2015-ACT-006
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 9,795 reports from 154 sources, 1,539 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs