Vulnerability Description
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Flash Player | <= 11.2.202.438 |
| Linux | Linux Kernel | - |
| Apple | Mac Os X | - |
| Microsoft | Windows | - |
| Suse | Linux Enterprise Desktop | 11 |
| Suse | Linux Enterprise Workstation Extension | 12 |
| Microsoft | Internet Explorer | 10 |
| Microsoft | Windows 8 | - |
| Microsoft | Windows Rt | - |
| Microsoft | Windows Server 2012 | - |
| Microsoft | Windows 10 1507 | - |
| Microsoft | Windows 8.1 | - |
| Microsoft | Windows Rt 8.1 | - |
| Microsoft | Edge | - |
References
- http://helpx.adobe.com/security/products/flash-player/apsa15-01.htmlVendor Advisory
- http://helpx.adobe.com/security/products/flash-player/apsb15-03.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00027.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00031.htmlMailing ListThird Party Advisory
- http://malware.dontneedcoffee.com/2015/01/unpatched-vulnerability-0day-in-flash.Third Party Advisory
- http://secunia.com/advisories/62432Broken Link
- http://secunia.com/advisories/62543Broken Link
- http://secunia.com/advisories/62650Broken Link
- http://secunia.com/advisories/62660Broken Link
- http://secunia.com/advisories/62740Broken Link
- http://security.gentoo.org/glsa/glsa-201502-02.xmlThird Party Advisory
- http://www.securityfocus.com/bid/72283Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1031597Broken LinkThird Party AdvisoryVDB Entry
- https://technet.microsoft.com/library/security/2755801PatchVendor Advisory
- http://helpx.adobe.com/security/products/flash-player/apsa15-01.htmlVendor Advisory
FAQ
What is CVE-2015-0311?
CVE-2015-0311 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute ...
How severe is CVE-2015-0311?
CVE-2015-0311 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-0311?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Flash Player, Linux Linux Kernel, Apple Mac Os X, Microsoft Windows, Suse Linux Enterprise Desktop.