Adobe Security Bulletin

Security Advisory for Adobe Flash Player

Release date: January 22, 2015

Last updated: January 24, 2015

Vulnerability identifier: APSA15-01

CVE number: CVE-2015-0311

Platform: All Platforms


A critical vulnerability (CVE-2015-0311) exists in Adobe Flash Player and earlier versions for Windows and Macintosh.  Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.  We are aware of reports that this vulnerability is being actively exploited in the wild via drive-by-download attacks against systems running Internet Explorer and Firefox on Windows 8.1 and below. 

UPDATE (January 24): Users who have enabled auto-update for the Flash Player desktop runtime will be receiving version beginning on January 24. This version includes a fix for CVE-2015-0311. Adobe expects to have an update available for manual download during the week of January 26, and we are working with our distribution partners to make the update available in Google Chrome and Internet Explorer 10 and 11. For more information on updating Flash Player please refer to this post.  

Affected software versions

  • Adobe Flash Player and earlier versions for Windows and Macintosh
  • Adobe Flash Player and earlier 13.x versions
  • Adobe Flash Player and earlier versions for Linux

To verify the version of Adobe Flash Player installed on your system, access the About Flash Player page, or right-click on content running in Flash Player and select "About Adobe (or Macromedia) Flash Player" from the menu. If you use multiple browsers, perform the check for each browser you have installed on your system.

Severity ratings

Adobe categorizes this as a critical vulnerability.


January 24, 2015: Updated to include Flash Player version delivered via auto-update.   

January 24, 2015: Updated to reflect reports that Windows 8.1 is also affected by CVE-2015-0311.