CVE detail
CVE-2015-7645
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
35 source links · newest first
- The evolutions of APT28 attacksSecurity Affairs
Analyzing how tactics, techniques and procedures of the Russia-linked APT28 cyberespionage group evolve over the time. APT28 is a well known Russian cyber espionage group attributed, with a medium level of confidence, to Russian military intelligence agency GRU (by CrowdStrike). It is also known as Sofacy Group (by Kaspersky) or STRONTIUM (by Microsoft) and it’s used to target Aereospace, Defence, Governmente Agencies, International […]
newssecurityaffairs.comDec 5, 2019, 6:41 AM - APT28 group is rushing to exploit recent CVE-2017-11292 Flash 0-Day before users apply the patchesSecurity Affairs
The APT28 group is trying to exploit the CVE-2017-11292 Flash zero-day before users receive patches or update their systems. Security experts at Proofpoint collected evidence of several malware campaigns, powered by the Russian APT28 group, that rely on a Flash zero-day vulnerability that Adobe patched earlier this week. According to the experts who observed attacks on organizations […]
newssecurityaffairs.comOct 22, 2017, 11:29 AM According to a new report published by FireEye, crooks have been using the Neptune exploit kit to deliver cryptocurrency miners via malvertising campaigns. According to experts at FireEye, crooks are exploiting the Neptune exploit kit (aka Terror EK, Eris, and Blaze) to delivery cryptocurrency miners via malvertising campaigns. The Neptune exploit kit was first spotted in January and was […]
newssecurityaffairs.comAug 23, 2017, 8:10 AM- Russia-linked hacker group APT28 continues to target MontenegroSecurity Affairs
Once again, Montenegro was targeted by the Russia-linked hacker group APT28, according to the experts it is just the beginning. On June 5 Montenegro officially joined NATO alliance despite the strong opposition from Russian Government that threatened to retaliate. Cybersecurity experts believe that a new wave of attacks from the cyberspace will hit the state. In February, for […]
newssecurityaffairs.comJun 7, 2017, 12:22 PM Hackers linked to Russia launched cyberattacks on the Montenegro government just months before the country joined the North Atlantic Treaty Organization (NATO) and experts believe these attacks will likely continue.
newswww.securityweek.comJun 7, 2017, 8:58 AM- Exploit kits: Winter 2017 reviewMalwarebytes Labs
A few months have passed since our Fall 2016 review of the most common exploit kits we are seeing in our telemetry and honeypots. Today, we take another look at the current (bleak) EK scene by going over RIG, Sundown, Neutrino and Magnitude. There haven’t been any major changes in the past little while and exploit kit-related infections remain low compared to those via malicious spam. This is in part due to the lack of fresh and reliable exploits in today’s drive-by landscape. Pseudo-Darkleech and EITest are the most popular redirection campaigns from compromised websites. They refer to code that is injected into – for the most part – WordPress , Joomla , or Drupal websites and automatically redirects visitors to an exploit kit landing page. Malvertising campaigns keep fuelling redirections to exploit kits as well, but can greatly vary in size and impact. The daily malverts from shady ad networks continue unchanged while the larger attacks going after top ad networks and publishers co…
newswww.malwarebytes.comMar 8, 2017, 5:00 PM It’s a new year and while some things change, some things stay the same (or similar). There’s lots of FUD about the sophisticated cyber attacks that are multi-threaded and obfuscated. Certainly there are attacks that fall into this category, but if you look at all of the cybercrime activity from the past year, it’s clear that the majority of threats do not have the level of sophistication that is often talked about.
newswww.securityweek.comJan 20, 2017, 4:16 PMBased on an analysis in 2015 of over 100 exploit kits (EKs) and known vulnerabilities, Adobe Flash was the unfortunate winner of the most frequently exploited product. Now that it’s 2017, companies are joking that maybe it’s time to give Flash the old heave ho’ to retirement. While Adobe has worked tirelessly to make Flash more […]
newswww.csoonline.comJan 17, 2017, 7:00 PM- New Terror Exploit Kit EmergesSecurityWeek
After the fall of the Nuclear and Angler exploit kits (EKs), overall activity generated from exploit kits has dropped to only a fraction of what used to be.
newswww.securityweek.comJan 10, 2017, 4:59 PM Recently, Palo Alto Networks Unit 42 reported on a new exploitation platform that we called “DealersChoice” in use by the Sofacy group (AKA APT28, Fancy Bear, STRONTIUM, Pawn Storm, Sednit). As outlined in our original posting, the DealersChoice exploitation platform generates malicious RTF documents which in turn use embedded OLE Word documents. These embedded OLE
vendorunit42.paloaltonetworks.comDec 15, 2016, 3:00 AM- A week in security (Dec 04 – Dec 10)Malwarebytes Labs
Last week we launched Malwarebytes 3.0, our next-generation antivirus replacement. We also touched on domain generating algorithms (DGA), went up-close and…
newswww.malwarebytes.comDec 11, 2016, 5:00 PM - Adobe Flash Player flaws remain the most used by Exploit KitsSecurity Affairs
Experts from the firm Recorded Future published a report on the most common vulnerabilities used by threat actors in the exploit kits. Recorded Future published an interesting report on the most common vulnerabilities used by threat actors in the exploit kits. The experts observed that Adobe Flash Player and Microsoft products (Internet Explorer, Silverlight, Windows) continue […]
newssecurityaffairs.comDec 6, 2016, 8:18 PM The most common vulnerabilities used by exploit kits in the past year affect Flash Player, Windows, Internet Explorer and Silverlight, according to a report published on Tuesday by threat intelligence firm Recorded Future.
newswww.securityweek.comDec 6, 2016, 3:28 PMUnit 42 has reported on various Sofacy group attacks over the last year, most recently with a post on Komplex, an OS X variant of a tool commonly used by the Sofacy group. In the same timeframe of the Komplex attacks, we collected several weaponized documents that use a tactic previously not observed in use
vendorunit42.paloaltonetworks.comOct 17, 2016, 8:00 PMAdobe’s Flash Player might be the most targeted product when criminal exploit kits are involved, but Microsoft products such as Office, Windows and Internet Explorer take center stage when Russian advanced persistent threat (APT) groups are involved.
newswww.securityweek.comAug 5, 2016, 2:10 PMFireEye has shared some technical details on the Flash Player zero-day that was patched last week by Adobe and revealed that attackers have been exploiting the vulnerability via specially crafted Microsoft Office documents.
newswww.securityweek.comMay 16, 2016, 6:22 PM- Magnitude EK Malvertising Déjà VuMalwarebytes Labs
During the past few days we have witnessed an increase in the number of malvertising incidents involving the Magnitude exploit kit. The last…
newswww.malwarebytes.comFeb 23, 2016, 5:00 PM - Experts warn Neutrino and RIG exploit kit activity spikeSecurity Affairs
Security experts at Heimdal Security are warning a spike in cyber attacks leveraging the popular Neutrino and RIG exploit kit. Cyber criminals always exploit new opportunities and users’ bad habits, now crooks behind the recent campaigns relying on Neutrino and RIG exploit kits are ramping up attacks against users that haven’s patched their Adobe Flash software. “It […]
newssecurityaffairs.comJan 12, 2016, 9:35 AM - Exploit Kits Mutate, Increase Activity: ReportSecurityWeek
Security researchers have observed an increase in exploit kit (EK) activity in the beginning of this year, coupled with a series of mutations, which include spreading more malware, Heimdal Security reports.
newswww.securityweek.comJan 6, 2016, 6:21 PM - Malvertising Campaign via Pop-under Ads Sends CryptoWall 4Malwarebytes Labs
We have caught a new malvertising campaign on the PopAds network launching the Magnitude exploit kit via pop-under ads.A pop-under is an ad window…
newswww.malwarebytes.comJan 6, 2016, 5:00 PM - Spike in Malvertising Attacks Via Nuclear EK Pushes RansomwareMalwarebytes Labs
We’ve been monitoring a malvertising campaign very closely as it really soared during the past week. The actors involved seem to be…
newswww.malwarebytes.comDec 10, 2015, 5:00 PM - Malvertising Hits DailyMotion, Serves Up Angler EKMalwarebytes Labs
We have been tracking an attack via .eu sites for several days but were missing the final payload. However, this changed when we…
newswww.malwarebytes.comDec 6, 2015, 5:00 PM Update (12/03): AdXpansion contacted us with the following statement:Adxpansion can confirm that these ads were disabled within hours of first being reported…
newswww.malwarebytes.comDec 1, 2015, 5:00 PM- Magnitude Exploit Kit Activity Increases Via Malvertising AttacksMalwarebytes Labs
During the past few days we have noticed a higher than usual number of malvertising attacks pushing the Magnitude exploit kit –…
newswww.malwarebytes.comNov 12, 2015, 5:00 PM The recently discovered CVE-2015-7645 zero-day vulnerability in Adobe Flash Player has been already added to Angler Exploit Kit (EK) and Nuclear EK, anti-malware firm Malwarebytes reported .
newswww.securityweek.comNov 3, 2015, 2:11 AM- Recent Flash Zero-Day Now Part of Exploit KitsMalwarebytes Labs
The Adobe Flash Player continues to be the favourite browser plugin threat actors have been focusing on this year. The recent zero-day…
newswww.malwarebytes.comOct 29, 2015, 5:00 PM Adobe updated Shockwave Player on Tuesday to address a critical vulnerability that can be exploited for arbitrary code execution.
newswww.securityweek.comOct 28, 2015, 8:55 AMOracle has patched a Java zero-day exploited by the Russia-linked advanced persistent threat (APT) group known as “Pawn Storm” in attacks aimed at NATO member countries and the White House.
newswww.securityweek.comOct 21, 2015, 10:32 AMAdobe released a patch for a critical vulnerability in Flash Player faster than it originally anticipated in response to high-profile cyberespionage attacks against governmental targets. The latest Flash Player updates released Friday address a flaw that’s already exploited by a Russian espionage group known as Pawn Storm, as well as two other critical vulnerabilities reported […]
newswww.csoonline.comOct 19, 2015, 11:44 AMAdobe has released Flash Player updates to address the zero-day vulnerability exploited by the Russia-linked Pawn Storm threat group in attacks aimed at Foreign Affairs Ministries.
newswww.securityweek.comOct 19, 2015, 6:07 AM- A Week in Security (Oct 11 – Oct 17)Malwarebytes Labs
Last week, we touched on Mozilla’s add-on guidelines for the Firefox browser; questioned the possibility of adware using the popular compression…
newswww.malwarebytes.comOct 18, 2015, 5:00 PM Despite both Microsoft and Adobe releasing patches on Tuesday (10/13/2015), a critical Flash zero-day flaw remains unpatched in Adobe’s latest update. Despite both Microsoft and Adobe releasing critical patches on Tuesday (10/13/2015), a critical zero-day vulnerability remains unpatched in Adobe’s latest update. As per Adobe APSA15-05, this vulnerability (CVE-2015-7645) remains unpatched is actively being exploited in-the-wild. Adobe plans […]
newssecurityaffairs.comOct 16, 2015, 4:51 AM- Adobe says Flash fix will ship next weekCSO Online
On Wednesday, Adobe confirmed reports from Trend Micro surrounding a new vulnerability in Flash that’s being used in attacks against high-profile targets in government affairs. The vulnerability has been tied to a number of Phishing campaigns that are part of what Trend Micro is calling Operation Pawn Storm. Some of the earliest attacks date back […]
newswww.csoonline.comOct 15, 2015, 11:00 AM Adobe announced on Wednesday that it expects to release a patch for the recently disclosed Flash Player zero-day exploited in targeted attacks by a Russian threat group during the week of October 19.
newswww.securityweek.comOct 15, 2015, 5:44 AM- New Flash Player Zero-Day in The Wild (updated)Malwarebytes Labs
Update(2): 10/16Adobe releases a fix to patch this vulnerability with Flash Player version 19.0.0.226. You should download the latest version immediately…
newswww.malwarebytes.comOct 13, 2015, 5:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2015-5119CVSS 9.8 · Critical
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows…
- CVE-2015-3113CVSS 9.8 · Critical
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attac…
- CVE-2015-8651CVSS 8.8 · High
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Ado…
- CVE-2015-3043CVSS 9.8 · Critical
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cau…
- CVE-2016-4171CVSS 9.8 · Critical
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
KEV listed12 mentions - CVE-2016-4155CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…