CVE-2015-3105 — AIR
CVE-2015-3105 is a Buffer Overflow vulnerability in adobe air. 2 public exploit references exist, so weaponization risk is real. No vendor fix is recorded yet; mitigation options are listed below.
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before…
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Description
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Affected Products
airadobeair sdkadobeair sdk \& compileradobeflash playeradobeandroidgoogleResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Adobe Flash Player - Drawing Fill Shader Memory Corruption (Metasploit)
by Metasploit · Jun 30, 2015
Detection & mitigation playbook
Vendor / applianceDetect
Inventory every adobe air deployment and check each version against the affected-products list above.
Remediation status
No patch has shipped for CVE-2015-3105 yet — track the adobe air advisory for a fixed release and apply the workarounds below in the meantime.
Mitigate without a patch
Constrain what reaches the vulnerable code: limit the size and shape of untrusted input, isolate the affected component in a sandboxed or least-privileged process, and enable the platform's memory-safety mitigations (ASLR, stack protector, hardened allocator) so an out-of-bounds access is more likely to fail closed than to be exploitable. Alongside that, restrict the management interface to trusted networks and apply the vendor's recommended configuration mitigations.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat Enterprise Linux 5 Supplementary | flash-plugin-0:11.2.202.466-1.el5 | RHSA-2015:1086 |
Frequently Asked Questions
Is CVE-2015-3105 being exploited in your environment?
Detect and block the exploit chain at execution, on systems you cannot patch yet.