CVE-2015-7662
Description
Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allow remote attackers to bypass intended access restrictions and write to files via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Adobe Flash Player before 18.0.0.261/19.0.0.245 (Windows/OS X) or 11.2.202.548 (Linux) and AIR before 19.0.0.241 allow remote attackers to bypass access restrictions and write to files via unspecified vectors.
Vulnerability
Adobe Flash Player versions prior to 18.0.0.261, 19.x prior to 19.0.0.245 on Windows and OS X, and versions prior to 11.2.202.548 on Linux, along with Adobe AIR, AIR SDK, and AIR SDK & Compiler before 19.0.0.241, contain a vulnerability that allows remote attackers to bypass intended access restrictions and write to files via unspecified vectors [1], [2], [3]. The official description does not specify the exact code path or required configuration, but the flaw is addressed in the security updates referenced by the advisories [1], [2], [3].
Exploitation
An attacker can exploit this vulnerability remotely by crafting a malicious SWF file that, when loaded by a victim using a vulnerable version of Flash Player, triggers the file-write operation [1], [2], [3]. No authentication is required, and the user interaction is limited to visiting a page containing the malicious content. The vulnerability allows the attacker to write arbitrary files to the victim's system, bypassing security restrictions [1], [2], [3].
Impact
Successful exploitation enables an attacker to write arbitrary files to the file system of the victim's system, effectively bypassing the intended access restrictions [1], [2], [3]. This could lead to further compromise, such as writing malicious executables or modifying system files, depending on the privileges of the Flash Player process. The impact is rated as critical by Red Hat and other vendors [1], [2], [3].
Mitigation
Adobe released fixed versions: Flash Player 18.0.0.261, 19.0.0.245 for Windows/OS X, and 11.2.202.548 for Linux; AIR/AIR SDK/AIR SDK & Compiler updated to 19.0.0.241 [1], [2], [3]. Users should upgrade immediately. Red Hat provided updated packages for RHEL 5 Supplementary [2], and Gentoo issued a GLSA recommending upgrade to 11.2.202.548 [3]. No workarounds were disclosed [3].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
15cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*range: <=19.0.0.190
- (no CPE)range: <19.0.0.241
cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*range: <=19.0.0.213
- (no CPE)range: <19.0.0.241
cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:*range: <=19.0.0.213
- (no CPE)range: <19.0.0.241
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*range: <=11.2.202.540
- cpe:2.3:a:adobe:flash_player:19.0.0.185:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:19.0.0.207:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:flash_player:19.0.0.226:*:*:*:*:*:*:*
- Range: <18.0.0.261, <19.0.0.245 (Windows/OS X), <11.2.202.548 (Linux)
- osv-coords4 versionspkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012
< 11.2.202.548-0.26.1+ 3 more
- (no CPE)range: < 11.2.202.548-0.26.1
- (no CPE)range: < 11.2.202.548-0.26.1
- (no CPE)range: < 11.2.202.548-111.1
- (no CPE)range: < 11.2.202.548-111.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- helpx.adobe.com/security/products/flash-player/apsb15-28.htmlnvdPatchVendor Advisory
- lists.opensuse.org/opensuse-updates/2015-11/msg00071.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-2023.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-2024.htmlnvd
- www.securityfocus.com/bid/77535nvd
- www.securitytracker.com/id/1034111nvd
- security.gentoo.org/glsa/201511-02nvd
News mentions
0No linked articles in our index yet.