Adobe Flash Player vulnerability
Use-after-free vulnerability in Adobe Flash Player's ActionScript 3 ByteArray class enables remote code execution. Actively exploited in the wild with high EPSS score.
Today item — known-exploited.
A use-after-free memory corruption flaw in Flash Player's ByteArray implementation allows attackers to achieve arbitrary code execution on vulnerable systems. The vulnerability is actively exploited and poses significant risk to deployed Flash installations.
Is it exploitable?
— the evidence, ranked above the scoreWho’s exploiting it?
— attribution turns risk into urgencyNo confirmed (advisory-backed) threat-actor attribution is established for this record. Absence of a named actor is not absence of compromise — see Coverage & confidence.
These are not confirmed attribution and do not name this record’s headline actor. Each is tier-labeled and cited; an inferred link is a structural ATT&CK chain (a group uses a tool whose reference cites this CVE), never a statement that the source names the group.
ATT&CK attributes gh0st RAT (S0032) to Andariel ↗, and that software’s ATT&CK reference cites this CVE. Structural chain, not a direct naming of the group — shown as inferred only. source ↗
ATT&CK attributes gh0st RAT (S0032) to Kimsuky ↗, and that software’s ATT&CK reference cites this CVE. Structural chain, not a direct naming of the group — shown as inferred only. source ↗
ATT&CK attributes gh0st RAT (S0032) to TA459 ↗, and that software’s ATT&CK reference cites this CVE. Structural chain, not a direct naming of the group — shown as inferred only. source ↗
ATT&CK attributes gh0st RAT (S0032) to APT5 ↗, and that software’s ATT&CK reference cites this CVE. Structural chain, not a direct naming of the group — shown as inferred only. source ↗
ATT&CK attributes gh0st RAT (S0032) to APT41 ↗, and that software’s ATT&CK reference cites this CVE. Structural chain, not a direct naming of the group — shown as inferred only. source ↗
ATT&CK attributes gh0st RAT (S0032) to Axiom ↗, and that software’s ATT&CK reference cites this CVE. Structural chain, not a direct naming of the group — shown as inferred only. source ↗
ATT&CK attributes gh0st RAT (S0032) to Leviathan ↗, and that software’s ATT&CK reference cites this CVE. Structural chain, not a direct naming of the group — shown as inferred only. source ↗
ATT&CK attributes gh0st RAT (S0032) to Threat Group-3390 ↗, and that software’s ATT&CK reference cites this CVE. Structural chain, not a direct naming of the group — shown as inferred only. source ↗
ATT&CK attributes gh0st RAT (S0032) to PittyTiger ↗, and that software’s ATT&CK reference cites this CVE. Structural chain, not a direct naming of the group — shown as inferred only. source ↗
Why it matters
— the attack path, told twice: adversary, then boardFront door — unauthenticated access narrative 1
Keys to the kingdom — privilege/identity takeover narrative 2
Lateral reach — past segmentation narrative 3
What to do
— defensible action- Remediate per the vendor advisory — confirm the fixed build for your version and verify exposure.1