VYPR
Unrated severityNVD Advisory· Published Aug 14, 2015· Updated May 6, 2026

CVE-2015-5127

CVE-2015-5127

Description

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5130, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550, CVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5559, CVE-2015-5561, CVE-2015-5563, CVE-2015-5564, and CVE-2015-5565.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Use-after-free in Adobe Flash Player's DisplacementMapFilter.mapBitmap handling enables arbitrary code execution.

Vulnerability

A use-after-free vulnerability exists in Adobe Flash Player due to improper handling of BitmapData objects when setting the DisplacementMapFilter.mapBitmap property [2]. This allows an attacker to free a memory object and then reference it, leading to code execution. Affected versions include Flash Player before 18.0.0.232 on Windows and OS X, before 11.2.202.508 on Linux, and Adobe AIR before 18.0.0.199 [1][3].

Exploitation

An attacker can exploit this by crafting a malicious SWF file that manipulates BitmapData and DisplacementMapFilter objects. The provided reproduction case [2] involves compiling an ActionScript 2 (AS2) file, manually modifying bytes to trigger the issue, then serving the SWF via a web browser. User interaction is required (e.g., opening a web page containing the SWF). The use-after-free is triggered when the Flash player dereferences a controlled memory address [2].

Impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running the Flash Player. This can lead to full system compromise, including data theft, installation of malware, or further network attacks. The vulnerability is classified as critical with a high CVSS score.

Mitigation

Adobe released fixed versions in August 2015: Flash Player 18.0.0.232 (Windows/OS X), 11.2.202.508 (Linux), and AIR 18.0.0.199 [1][3]. Users should update immediately. There is no known workaround. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog at the time of writing.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

11

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.