CVE-2015-7645Active Exploitation(adobe / enterprise_linux_desktop)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch adobe enterprise_linux_desktop systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.

5.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-03-24. The impacted product is end-of-life and should be disconnected if still in use.

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux_desktop
  • enterprise_linux_eus
  • enterprise_linux_server
  • enterprise_linux_server_from_rhui

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
enterprise_linux_desktopenterprise_linux_eusenterprise_linux_serverenterprise_linux_server_from_rhuienterprise_linux_workstationevergreenflash_playerlinux_enterprise_desktoplinux_enterprise_workstation_extensionlinux_kernel

11 versions affected across 13 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-01: 1Active Exploitation · 2026-05-01: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-05-01: 105-01
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • DFIR Lab@DFIR_Lab
    Active Exploitation

    🚨 HIGH SEVERITY: CVE-2015-7645 | CVSS 7.8 Adobe Flash Player RCE via crafted SWF files. Actively exploited in the wild (Oct 2015). Affected: Flash 18.x-19.x (Win/Mac), 11.x (Linux) Action: Patch immediately #CVE #Vulnerability #PatchNow https://t.co/DCa641FN6U

    Post summary

    The tweet announces that CVE‑2015‑7645, a high‑severity RCE in Adobe Flash Player, was actively exploited in the wild in October 2015, and urges users to patch immediately.

    0000040
    11 followersView on X
CPE platform detail22 entries

22 of 22 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeflash_player---
Appadobeflash_player19.0.0.185--
Appadobeflash_player19.0.0.207--
OSapplemac_os_x---
OSlinuxlinux_kernel---
OSmicrosoftwindows---
OSopensuseevergreen11.4--
OSopensuseopensuse13.1--
OSopensuseopensuse13.2--
OSredhatenterprise_linux_desktop5.0--
OSredhatenterprise_linux_desktop6.0--
OSredhatenterprise_linux_eus6.7--
OSredhatenterprise_linux_server5.0--
OSredhatenterprise_linux_server6.0--
OSredhatenterprise_linux_server_from_rhui5.0--
OSredhatenterprise_linux_server_from_rhui6.0--
OSredhatenterprise_linux_workstation5.0--
OSredhatenterprise_linux_workstation6.0--
OSsuselinux_enterprise_desktop11--
OSsuselinux_enterprise_desktop11--
OSsuselinux_enterprise_desktop12--
OSsuselinux_enterprise_workstation_extension12--

Explore more