Skip to main content

CVE detail

CVE-2015-3043

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.

CVSS 9.8 · CriticalBuzz score 60.9KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 60.9

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 24.9 · diversity 11.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
24.9
11 evidence mentions in the snapshot
Diversity score
11.0
5 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
11 source links · newest first
  • The evolutions of APT28 attacksSecurity Affairs

    Analyzing how tactics, techniques and procedures of the Russia-linked APT28 cyberespionage group evolve over the time. APT28 is a well known Russian cyber espionage group attributed, with a medium level of confidence, to Russian military intelligence agency GRU (by CrowdStrike). It is also known as Sofacy Group (by Kaspersky) or STRONTIUM (by Microsoft) and it’s used to target Aereospace, Defence, Governmente Agencies, International […]

    newssecurityaffairs.comDec 5, 2019, 6:41 AM
  • Adobe’s Flash Player might be the most targeted product when criminal exploit kits are involved, but Microsoft products such as Office, Windows and Internet Explorer take center stage when Russian advanced persistent threat (APT) groups are involved.

    newswww.securityweek.comAug 5, 2016, 2:10 PM
  • An exploit for a Flash Player vulnerability patched by Adobe last week with the release of version 18.0.0.194 has been integrated into the Magnitude exploit kit.

    newswww.securityweek.comJun 29, 2015, 9:02 AM
  • Recent Flash Player 0-day Exploit Goes MainstreamMalwarebytes Labs

    Security firm FireEye released a report on June 23 about targeted attacks leveraging a Flash Player zero-day vulnerability (CVE-2015-3113) in Adobe Flash Player…

    newswww.malwarebytes.comJun 27, 2015, 5:00 PM
  • Researchers at Trend Micro say the zero-day vulnerability patched Tuesday by Adobe Systems has a similar underlying cause as an older flaw .

    newswww.securityweek.comJun 24, 2015, 9:03 PM
  • APT28, believed to consist of Russian hackers, has been spotted wielding two zero-day exploits in the latest targeted attack aimed at an “international government entity in an industry vertical that aligns with known APT28 targeting.”According to FireEye researchers, the group, which seems to be the same one behind the “Pawn Storm” campaigns and which has been recently found targeting NATO members and the White House, has been exploiting the Adobe Flash CVE-2015-3043 vulnerability and a … More →

    newswww.helpnetsecurity.comApr 20, 2015, 6:13 AM
  • FireEye recently detected a new highly targeted attack run by APT28 exploiting two zero-day flaws to compromise an “international government entity”. Security experts at FireEye have recently detected a new cyber espionage campaign, dubbed “Operation RussianDoll,” operated by the Russian APT28 group. This time the hackers run highly targeted attack by exploiting two zero-day vulnerabilities to target an “international […]

    newssecurityaffairs.comApr 19, 2015, 10:01 AM
  • FireEye said on Saturday that it recently detected a highly targeted attack exploiting two zero-day vulnerabilities in an effort to compromise an “international government entity” in an industry vertical that aligns with known targets hit by a threat actor group which FireEye calls APT28. FireEye has described APT28 as a skilled team of developers and operators collecting intelligence on defense and geopolitical issues that would clearly benefit Russia. The security firm previously traced cyber-espionage campaigns by the group that date back to 2007. FireEye said that it first detected the attacks on April 13th, 2015, when the attackers attempted to exploit two zero-day vulnerabilities, including a recently patched flaw in Adobe Flash (CVE-2015-3043) and a brand new one in Microsoft Windows (CVE-2015-1701). Through its analysis and technical indicators and command and control infrastructure, FireEye believes that the APT28 attackers are responsible for the campaign, which it is callin…

    newswww.securityweek.comApr 18, 2015, 7:25 PM
  • Adobe released a new version of Flash Player (17.0.0.169) for Windows and Macintosh, and for Linux (11.2.202.457). These security updates fix a host of critical vulnerabilities – 22 in all – most of which could lead to code execution and an attacker taking control of the affected system: Memory corruption vulnerabilities that could lead to code execution (CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, CVE-2015-3043) A type confusion vulnerability that could lead … More →

    newswww.helpnetsecurity.comApr 15, 2015, 3:50 AM
  • Microsoft released 11 security bulletins today to address vulnerabilities in a number of products, including a critical Office bug being exploited in the wild.

    newswww.securityweek.comApr 14, 2015, 7:08 PM
  • For April 2015 Patch Tuesday, Microsoft released 11 security bulletins, four of which are rated as critical, to address 26 vulnerabilities. Rated Critical All four critical security updates resolve remote code execution (RCE) vulnerabilities. MS15-033 should be your top priority, according to Qualys CTO Wolfgang Kandek, as it addresses a zero-day vulnerability in Microsoft Office, […]

    newswww.csoonline.comApr 14, 2015, 7:04 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence