# Adobe Flash Player use-after-free under active exploitation

Published: 2015-02-09 · Severity: high
Canonical: https://vorant.io/reports/e93c741e-c677-58dc-9ff2-80f9b8389c69/adobe-flash-player-use-after-free-under-active-exploitation

> CVE-2015-0313, a use-after-free in Adobe Flash Player, is actively exploited via malicious ads on high-traffic sites; patch to version 16.0.0.305 immediately.

The CERT-FR alerts to active exploitation of CVE-2015-0313, a use-after-free vulnerability in Adobe Flash Player affecting versions 16.0.0.296 and earlier on Windows/macOS and 13.x before 13.0.0.264 on Linux. The flaw exists in the FlashCC memory-access acceleration feature, where a freed ByteArray object leaves a dangling pointer in the ApplicationDomain's domainMemory field. An attacker sprays the heap with Vector objects, then uses domainMemory to read and write arbitrary process memory, enabling remote code execution within the Flash sandbox. The vulnerability has been exploited in the wild via compromised ad networks serving malicious content on sites including Dailymotion, Huffington Post, and Answers.com. Exploitation observed on Windows across all versions including 8.1. Adobe released patch 16.0.0.305 on 4 February 2015 and auto-deployed it to users with automatic updates enabled. The bulletin also addresses SSDP reflection attacks enabling DDoS amplification and recommends disabling UPnP services or restricting SSDP traffic at network boundaries.

## Mentioned in this report

- Vulnerabilities: CVE-2015-0313 (KEV)

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2015-ACT-006

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e93c741e-c677-58dc-9ff2-80f9b8389c69/adobe-flash-player-use-after-free-under-active-exploitation.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
