Memory corruption in Adobe products - CVE-2015-3043
Published: January 26, 2017 / Updated: November 20, 2020
Vulnerability details
The weakness exists due to boundary error. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code with privileges of the current user.
Successful exploitation results in arbitrary code execution on the vulnerable system.
Note: the vulnerability was being actively exploited.
Affected software
Adobe Flash Player
Adobe AIR
How to mitigate CVE-2015-3043
Links to Public Exploits and PoC-codes
- Exploit #2118 - Exploit (cve-2015-3043 flash exploit) (March 18, 2020)
- Exploit #922 - Adobe Flash Player - Nellymoser Audio Decoding Buffer Overflow (Metasploit) (March 18, 2020)
- Exploit #923 - Adobe Flash Player - Nellymoser Audio Decoding Buffer Overflow (Metasploit) (March 18, 2020)
- Exploit #1801 - Adobe Flash Player Nellymoser Audio Decoding Buffer Overflow (March 18, 2020)