VYPR
Unrated severityNVD Advisory· Published Nov 11, 2015· Updated May 6, 2026

CVE-2015-7661

CVE-2015-7661

Description

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via a crafted getBounds call, a different vulnerability than CVE-2015-7651, CVE-2015-7652, CVE-2015-7653, CVE-2015-7654, CVE-2015-7655, CVE-2015-7656, CVE-2015-7657, CVE-2015-7658, CVE-2015-7660, CVE-2015-7663, CVE-2015-8042, CVE-2015-8043, CVE-2015-8044, and CVE-2015-8046.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Use-after-free vulnerability in Adobe Flash Player's getBounds method allows remote code execution via crafted SWF file.

Vulnerability

CVE-2015-7661 is a use-after-free vulnerability in Adobe Flash Player affecting versions before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X, and before 11.2.202.548 on Linux. It also impacts Adobe AIR before 19.0.0.241 and related SDK versions [1]. The vulnerability resides in the getBounds method of ActionScript 2 (AS2) movies, where improper memory management can lead to a dangling pointer being reused after being freed [3].

Exploitation

To exploit this vulnerability, an attacker must craft a malicious SWF file that manipulates the AS2 stack and then calls the getBounds method, triggering a use-after-free condition. User interaction is required, as the target must visit a malicious web page or open the malicious file in a vulnerable Flash Player instance [3]. No additional authentication or network privileges are needed beyond enticing the user to load the content.

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the current process, typically the web browser or Flash Player plugin. This can lead to full system compromise, including data theft, installation of malware, or further escalation of privileges [2][3]. The CVSS score is 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P) [3].

Mitigation

Adobe released fixed versions: Flash Player 18.0.0.261 and 19.0.0.245 for Windows/OS X, and 11.2.202.548 for Linux; AIR 19.0.0.241 and corresponding SDK updates. Red Hat and Gentoo published security advisories urging immediate updates [1][2][4]. No known workaround exists; users should apply patches promptly.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

15

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.