Skip to content

CVE-2015-0311

is CVE-2015-0311real, exploitable, or a false positive? Here's the community ground truth.

Critical · CVSS 9.8EPSS 85.8%CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.

Published

Embed this verdict
TruePositive verdict for CVE-2015-0311
Markdown
[![TruePositive verdict](https://www.truepositive.app/cve/CVE-2015-0311/badge.svg)](https://www.truepositive.app/cve/CVE-2015-0311)
HTML
<a href="https://www.truepositive.app/cve/CVE-2015-0311"><img src="https://www.truepositive.app/cve/CVE-2015-0311/badge.svg" alt="TruePositive verdict for CVE-2015-0311"></a>

Live badge — updates automatically as the community verdict changes.

Community ground truth

Community verdict

2 verdicts
Not a real issue

Includes TruePositive's curated baseline from public sources — community verdicts accrue on top.

Pick your verdict — we'll save it right after a quick sign-in.

Community real-world severity: Critical (Critical 2) — CVSS base score 9.8

In line with its CVSS base score.

Field notes & remediation

Verdicts are the quick signal — notes are the evidence and fixes behind them.

  • 0
    Field note · Diego RamírezCurated

    Adobe Flash Player Remote Code Execution Vulnerability — Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code. Listed in the CISA KEV catalog (added 2022-04-13) — confirmed exploited in the wild, not theoretical. FIRST EPSS puts the chance of exploitation in the next 30 days at ~86%. Treat it as real and prioritize remediation over triage.

  • 0
    Remediation · Marco FerriCurated

    Required action for Adobe Flash Player: The impacted product is end-of-life and should be disconnected if still in use. CISA set a federal remediation due date of 2022-05-04. After patching, verify the vulnerable path is no longer reachable before closing the finding.