Oval Definition:oval:org.cisecurity:def:1254
Revision Date:2016-11-11Version:21
Title:Vulnerability in Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 - CVE-2015-0310
Description:Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2015-0310
Platform(s):Microsoft Windows 10
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s):ActiveX Control
Adobe Flash Player
Pepper Flash
Definition Synopsis
  • Adobe Flash Player
  • Adobe Flash Player is installed
  • AND Adobe Flash Player version
  • Check if Adobe Flash Player (ESR) version is less than 13.0.0.262
  • OR Adobe Flash Player
  • Check if Adobe Flash Player version is less than 16.0.0.287
  • AND Check if Adobe Flash Player version is greater than or equal to 14.0.0.0
  • OR Pepper Flash for Google Chrome version
  • Google Chrome is installed
  • AND Check if Pepper Flash for Google Chrome version is less than 16.0.0.287
  • OR Flash.ocx section
  • ActiveX Control is installed
  • AND Flash.ocx versions section
  • Check if the ESR version of Flash.ocx is less than 13.0.0.262
  • OR ActiveX Control version
  • Check if Flash*.ocx version is less than 16.0.0.287
  • AND Check if Flash*.ocx version is greater than or equal to 14.0.0.0
  • BACK