A double free vulnerability exists in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X, and before 11.2.202.457 on Linux. The flaw allows attackers to execute arbitrary code via unspecified vectors. The vulnerability was widely exploited by multiple exploit kits (Angler, Neutrino, Nuclear Pack, RIG, Magnitude, Fiesta) shortly after disclosure, primarily targeting Internet Explorer 11 on Windows 7 via malvertising and obfuscated SWF payloads.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting a use-after-free vulnerability (CVE-2015-0359) in Adobe Flash Player (up to version 17.0.0.134) on Windows systems. The exploit is delivered via a malicious SWF file served to the victim's browser (Internet Explorer 8/11 or Firefox) on Windows 7 SP1 or 8.1. The module generates an HTML page embedding the SWF, which exploits the vulnerability to achieve arbitrary code execution in the browser context. The payload is customizable and can be any Metasploit-supported Windows payload. The module references several public advisories and blog posts for further information. The structure is typical for a Metasploit browser exploit: it includes methods for serving the SWF and HTML, generating the payload, and handling incoming requests. The only fingerprintable network endpoint is the reference to the official Macromedia Flash Player ActiveX control CAB file, used in the generated HTML. The exploit is operational and can be used to compromise vulnerable systems in real-world scenarios.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.