« Volver al listado

CVE-2015-8644

Estado: ModificadaAlta (8.8)—💥 Exploit

Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion."

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

💥 Exploits públicos

Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-8644",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-12-28T23:59:12.397",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00045.html",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00046.html",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00047.html",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00048.html",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2015-2697.html",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/79704",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1034544",
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388",
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680",
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722",
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://helpx.adobe.com/security/products/flash-player/apsb16-01.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://security.gentoo.org/glsa/201601-03",
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://www.exploit-db.com/exploits/39476/",
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00045.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00046.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00047.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00048.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2015-2697.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/79704",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1034544",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://helpx.adobe.com/security/products/flash-player/apsb16-01.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/201601-03",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/39476/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code by leveraging an unspecified \"type confusion.\""
    },
    {
      "lang": "es",
      "value": "Adobe Flash Player en versiones anteriores a 18.0.0.324 y 19.x y 20.x en versiones anteriores a 20.0.0.267 en Windows y OS X y en versiones anteriores a 11.2.202.559 en Linux, Adobe AIR en versiones anteriores a 20.0.0.233, Adobe AIR SDK en versiones anteriores a 20.0.0.233 y Adobe AIR SDK & Compiler en versiones anteriores a 20.0.0.233 permite a atacantes ejecutar código arbitrario aprovechándose de una \"confusión de tipo\" no especificada."
    }
  ],
  "lastModified": "2026-06-17T00:34:56.590",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99CE27CD-BCFA-4065-AD5A-A6206C15AC37",
              "versionEndIncluding": "18.0.0.268"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:19.0.0.185:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "130D56D9-BFAD-44AB-BA04-1E6E2F18A049"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:19.0.0.207:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0CE2650-25EB-446E-B2C9-631177740E87"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:19.0.0.226:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBAE999D-B558-4714-854D-42D45A7A48BB"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:19.0.0.245:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E47897F-1045-4CED-B208-4BED652FAE6F"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:20.0.0.228:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1AA036B2-C5F2-4DCD-B414-05045E3575B9"
            },
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:20.0.0.235:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E3F4354-3066-45F0-8FE1-FB0496465C83"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0FF5999A-9D12-4CDD-8DE9-A89C10B2D574"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2CF61F35-5905-4BA9-AD7E-7DB261D2F256"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "140657B1-1638-48BD-95B5-565EF5CF5BE5",
              "versionEndIncluding": "11.2.202.554"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "155AD4FB-E527-4103-BCEF-801B653DEA37"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "95299551-EDD0-4F8F-9F18-C3049CB3A9F4",
              "versionEndIncluding": "20.0.0.204"
            },
            {
              "criteria": "cpe:2.3:a:adobe:air_sdk_\\&_compiler:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8338438E-18F8-4DCE-95E0-5FEFCEC15026",
              "versionEndIncluding": "20.0.0.204"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "340C4071-1447-477F-942A-8E09EA29F917"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0FF5999A-9D12-4CDD-8DE9-A89C10B2D574"
            },
            {
              "criteria": "cpe:2.3:o:google:android:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8255F035-04C8-4158-B301-82101711939C"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2CF61F35-5905-4BA9-AD7E-7DB261D2F256"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F5182AB-63F9-4BF3-B8A9-44B182E86A80",
              "versionEndIncluding": "20.0.0.204"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0FF5999A-9D12-4CDD-8DE9-A89C10B2D574"
            },
            {
              "criteria": "cpe:2.3:o:google:android:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8255F035-04C8-4158-B301-82101711939C"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2CF61F35-5905-4BA9-AD7E-7DB261D2F256"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "evaluatorComment": "<a href=\"http://cwe.mitre.org/data/definitions/843.html\">CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')</a>",
  "sourceIdentifier": "psirt@adobe.com"
}