Skip to main content

CVE detail

CVE-2015-7645

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.

CVSS 7.8 · HighBuzz score 69.5KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 69.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
35 evidence mentions in the snapshot
Diversity score
14.5
5 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
35 source links · newest first
  • The evolutions of APT28 attacksSecurity Affairs

    Analyzing how tactics, techniques and procedures of the Russia-linked APT28 cyberespionage group evolve over the time. APT28 is a well known Russian cyber espionage group attributed, with a medium level of confidence, to Russian military intelligence agency GRU (by CrowdStrike). It is also known as Sofacy Group (by Kaspersky) or STRONTIUM (by Microsoft) and it’s used to target Aereospace, Defence, Governmente Agencies, International […]

    newssecurityaffairs.comDec 5, 2019, 6:41 AM
  • The APT28 group is trying to exploit the CVE-2017-11292 Flash zero-day before users receive patches or update their systems. Security experts at Proofpoint collected evidence of several malware campaigns, powered by the Russian APT28 group, that rely on a Flash zero-day vulnerability that Adobe patched earlier this week. According to the experts who observed attacks on organizations […]

    newssecurityaffairs.comOct 22, 2017, 11:29 AM
  • According to a new report published by FireEye, crooks have been using the Neptune exploit kit to deliver cryptocurrency miners via malvertising campaigns. According to experts at FireEye, crooks are exploiting the Neptune exploit kit (aka Terror EK, Eris, and Blaze) to delivery cryptocurrency miners via malvertising campaigns. The Neptune exploit kit was first spotted in January and was […]

    newssecurityaffairs.comAug 23, 2017, 8:10 AM
  • Once again, Montenegro was targeted by the Russia-linked hacker group APT28, according to the experts it is just the beginning. On June 5 Montenegro officially joined NATO alliance despite the strong opposition from Russian Government that threatened to retaliate. Cybersecurity experts believe that a new wave of attacks from the cyberspace will hit the state. In February, for […]

    newssecurityaffairs.comJun 7, 2017, 12:22 PM
  • Hackers linked to Russia launched cyberattacks on the Montenegro government just months before the country joined the North Atlantic Treaty Organization (NATO) and experts believe these attacks will likely continue.

    newswww.securityweek.comJun 7, 2017, 8:58 AM
  • Exploit kits: Winter 2017 reviewMalwarebytes Labs

    A few months have passed since our Fall 2016 review of the most common exploit kits we are seeing in our telemetry and honeypots. Today, we take another look at the current (bleak) EK scene by going over RIG, Sundown, Neutrino and Magnitude. There haven’t been any major changes in the past little while and exploit kit-related infections remain low compared to those via malicious spam. This is in part due to the lack of fresh and reliable exploits in today’s drive-by landscape. Pseudo-Darkleech and EITest are the most popular redirection campaigns from compromised websites. They refer to code that is injected into – for the most part – WordPress , Joomla , or Drupal websites and automatically redirects visitors to an exploit kit landing page. Malvertising campaigns keep fuelling redirections to exploit kits as well, but can greatly vary in size and impact. The daily malverts from shady ad networks continue unchanged while the larger attacks going after top ad networks and publishers co…

    newswww.malwarebytes.comMar 8, 2017, 5:00 PM
  • It’s a new year and while some things change, some things stay the same (or similar). There’s lots of FUD about the sophisticated cyber attacks that are multi-threaded and obfuscated. Certainly there are attacks that fall into this category, but if you look at all of the cybercrime activity from the past year, it’s clear that the majority of threats do not have the level of sophistication that is often talked about.

    newswww.securityweek.comJan 20, 2017, 4:16 PM
  • Based on an analysis in 2015 of over 100 exploit kits (EKs) and known vulnerabilities, Adobe Flash was the unfortunate winner of the most frequently exploited product. Now that it’s 2017, companies are joking that maybe it’s time to give Flash the old heave ho’ to retirement. While Adobe has worked tirelessly to make Flash more […]

    newswww.csoonline.comJan 17, 2017, 7:00 PM
  • New Terror Exploit Kit EmergesSecurityWeek

    After the fall of the Nuclear and Angler exploit kits (EKs), overall activity generated from exploit kits has dropped to only a fraction of what used to be.

    newswww.securityweek.comJan 10, 2017, 4:59 PM
  • Recently, Palo Alto Networks Unit 42 reported on a new exploitation platform that we called “DealersChoice” in use by the Sofacy group (AKA APT28, Fancy Bear, STRONTIUM, Pawn Storm, Sednit). As outlined in our original posting, the DealersChoice exploitation platform generates malicious RTF documents which in turn use embedded OLE Word documents. These embedded OLE

    vendorunit42.paloaltonetworks.comDec 15, 2016, 3:00 AM
  • A week in security (Dec 04 – Dec 10)Malwarebytes Labs

    Last week we launched Malwarebytes 3.0, our next-generation antivirus replacement. We also touched on domain generating algorithms (DGA), went up-close and…

    newswww.malwarebytes.comDec 11, 2016, 5:00 PM
  • Experts from the firm Recorded Future published a report on the most common vulnerabilities used by threat actors in the exploit kits. Recorded Future published an interesting report on the most common vulnerabilities used by threat actors in the exploit kits. The experts observed that Adobe Flash Player and Microsoft products (Internet Explorer, Silverlight, Windows) continue […]

    newssecurityaffairs.comDec 6, 2016, 8:18 PM
  • The most common vulnerabilities used by exploit kits in the past year affect Flash Player, Windows, Internet Explorer and Silverlight, according to a report published on Tuesday by threat intelligence firm Recorded Future.

    newswww.securityweek.comDec 6, 2016, 3:28 PM
  • Unit 42 has reported on various Sofacy group attacks over the last year, most recently with a post on Komplex, an OS X variant of a tool commonly used by the Sofacy group. In the same timeframe of the Komplex attacks, we collected several weaponized documents that use a tactic previously not observed in use

    vendorunit42.paloaltonetworks.comOct 17, 2016, 8:00 PM
  • Adobe’s Flash Player might be the most targeted product when criminal exploit kits are involved, but Microsoft products such as Office, Windows and Internet Explorer take center stage when Russian advanced persistent threat (APT) groups are involved.

    newswww.securityweek.comAug 5, 2016, 2:10 PM
  • FireEye has shared some technical details on the Flash Player zero-day that was patched last week by Adobe and revealed that attackers have been exploiting the vulnerability via specially crafted Microsoft Office documents.

    newswww.securityweek.comMay 16, 2016, 6:22 PM
  • Magnitude EK Malvertising Déjà VuMalwarebytes Labs

    During the past few days we have witnessed an increase in the number of malvertising incidents involving the Magnitude exploit kit. The last…

    newswww.malwarebytes.comFeb 23, 2016, 5:00 PM
  • Security experts at Heimdal Security are warning a spike in cyber attacks leveraging the popular Neutrino and RIG exploit kit. Cyber criminals always exploit new opportunities and users’ bad habits, now crooks behind the recent campaigns relying on Neutrino and RIG exploit kits are ramping up attacks against users that haven’s patched their Adobe Flash software. “It […]

    newssecurityaffairs.comJan 12, 2016, 9:35 AM
  • Security researchers have observed an increase in exploit kit (EK) activity in the beginning of this year, coupled with a series of mutations, which include spreading more malware, Heimdal Security reports.

    newswww.securityweek.comJan 6, 2016, 6:21 PM
  • We have caught a new malvertising campaign on the PopAds network launching the Magnitude exploit kit via pop-under ads.A pop-under is an ad window…

    newswww.malwarebytes.comJan 6, 2016, 5:00 PM
  • We’ve been monitoring a malvertising campaign very closely as it really soared during the past week. The actors involved seem to be…

    newswww.malwarebytes.comDec 10, 2015, 5:00 PM
  • Malvertising Hits DailyMotion, Serves Up Angler EKMalwarebytes Labs

    We have been tracking an attack via .eu sites for several days but were missing the final payload. However, this changed when we…

    newswww.malwarebytes.comDec 6, 2015, 5:00 PM
  • Update (12/03): AdXpansion contacted us with the following statement:Adxpansion can confirm that these ads were disabled within hours of first being reported…

    newswww.malwarebytes.comDec 1, 2015, 5:00 PM
  • During the past few days we have noticed a higher than usual number of malvertising attacks pushing the Magnitude exploit kit –…

    newswww.malwarebytes.comNov 12, 2015, 5:00 PM
  • The recently discovered CVE-2015-7645 zero-day vulnerability in Adobe Flash Player has been already added to Angler Exploit Kit (EK) and Nuclear EK, anti-malware firm Malwarebytes reported .

    newswww.securityweek.comNov 3, 2015, 2:11 AM
  • Recent Flash Zero-Day Now Part of Exploit KitsMalwarebytes Labs

    The Adobe Flash Player continues to be the favourite browser plugin threat actors have been focusing on this year. The recent zero-day…

    newswww.malwarebytes.comOct 29, 2015, 5:00 PM
  • Adobe updated Shockwave Player on Tuesday to address a critical vulnerability that can be exploited for arbitrary code execution.

    newswww.securityweek.comOct 28, 2015, 8:55 AM
  • Oracle has patched a Java zero-day exploited by the Russia-linked advanced persistent threat (APT) group known as “Pawn Storm” in attacks aimed at NATO member countries and the White House.

    newswww.securityweek.comOct 21, 2015, 10:32 AM
  • Adobe released a patch for a critical vulnerability in Flash Player faster than it originally anticipated in response to high-profile cyberespionage attacks against governmental targets. The latest Flash Player updates released Friday address a flaw that’s already exploited by a Russian espionage group known as Pawn Storm, as well as two other critical vulnerabilities reported […]

    newswww.csoonline.comOct 19, 2015, 11:44 AM
  • Adobe has released Flash Player updates to address the zero-day vulnerability exploited by the Russia-linked Pawn Storm threat group in attacks aimed at Foreign Affairs Ministries.

    newswww.securityweek.comOct 19, 2015, 6:07 AM
  • A Week in Security (Oct 11 – Oct 17)Malwarebytes Labs

    Last week, we touched on Mozilla’s add-on guidelines for the Firefox browser; questioned the possibility of adware using the popular compression…

    newswww.malwarebytes.comOct 18, 2015, 5:00 PM
  • Despite both Microsoft and Adobe releasing patches on Tuesday (10/13/2015), a critical Flash zero-day flaw remains unpatched in Adobe’s latest update. Despite both Microsoft and Adobe releasing critical patches on Tuesday (10/13/2015), a critical zero-day vulnerability remains unpatched in Adobe’s latest update. As per Adobe APSA15-05, this vulnerability (CVE-2015-7645) remains unpatched is actively being exploited in-the-wild. Adobe plans […]

    newssecurityaffairs.comOct 16, 2015, 4:51 AM
  • On Wednesday, Adobe confirmed reports from Trend Micro surrounding a new vulnerability in Flash that’s being used in attacks against high-profile targets in government affairs. The vulnerability has been tied to a number of Phishing campaigns that are part of what Trend Micro is calling Operation Pawn Storm. Some of the earliest attacks date back […]

    newswww.csoonline.comOct 15, 2015, 11:00 AM
  • Adobe announced on Wednesday that it expects to release a patch for the recently disclosed Flash Player zero-day exploited in targeted attacks by a Russian threat group during the week of October 19.

    newswww.securityweek.comOct 15, 2015, 5:44 AM
  • New Flash Player Zero-Day in The Wild (updated)Malwarebytes Labs

    Update(2): 10/16Adobe releases a fix to patch this vulnerability with Flash Player version 19.0.0.226. You should download the latest version immediately…

    newswww.malwarebytes.comOct 13, 2015, 5:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence