AirApplication · Adobe

CVE-2015-7657

HIGH · 9.3 CVSS v2.0 Published 2015-11-11
Fix available
A fix is available. Upgrade to after 19.0.0.213 or later.
See remediation →
100/100
Remediation priority · Urgent
Remotely reachable No privileges Zero-click Patch available

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via crafted actionCallMethod arguments, a different vulnerability than CVE-2015-7651, CVE-2015-7652, CVE-2015-7653, CVE-2015-7654, CVE-2015-7655, CVE-2015-7656, CVE-2015-7658, CVE-2015-7660, CVE-2015-7661, CVE-2015-7663, CVE-2015-8042, CVE-2015-8043, CVE-2015-8044, and CVE-2015-8046.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis

A detailed technical summary for this CVE is being prepared.

Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.

NVD · CPE data
AirApplication
Affected:<= 19.0.0.190<= 19.0.0.213
Flash PlayerApplication
Affected:<= 18.0.0.255= 19.0.0.185= 19.0.0.207= 19.0.0.226<= 11.2.202.540
Air SdkApplication
Affected:<= 19.0.0.213
Air Sdk \& CompilerApplication
Affected:<= 19.0.0.213

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
M
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete

AV:N/AC:M/Au:N/C:C/I:C/A:C

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Upgrade available Upgrade to a release after 19.0.0.213
Vendor patch helpx.adobe.com →
Recommended fix High confidence

Flash Player: 18.0.0.261+ (Windows/OS X) or 11.2.202.548+ (Linux); AIR/AIR SDK/AIR SDK & Compiler: 19.0.0.241+

  1. Identify the installed Adobe product (Flash Player, AIR, AIR SDK, or AIR SDK & Compiler) and its exact version number
  2. For Flash Player: verify version is <= 18.0.0.255, or equals 19.0.0.185, 19.0.0.207, or 19.0.0.226
  3. For AIR: verify version is <= 19.0.0.190 or <= 19.0.0.213
  4. For AIR SDK or AIR SDK & Compiler: verify version is <= 19.0.0.213
  5. Download the patched version from the official Adobe security bulletin (APSB15-28) or Adobe's download center
  6. For Flash Player: upgrade to version 18.0.0.261 or later (Windows/OS X), or 11.2.202.548 or later (Linux)
  7. For AIR, AIR SDK, or AIR SDK & Compiler: upgrade to version 19.0.0.241 or later
  8. Restart the system or application to ensure the patched version is fully loaded
Caveat Adobe Flash Player is deprecated; consider migrating away from Flash-based applications as Adobe ended support in December 2020

Generated from the published advisory — verify against the referenced sources before acting.

We can identify the exact fixed release, upgrade, and verify it in staging — typical engagement from $1,950. Get the upgrade done

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2015-7657 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2015-7657 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data