| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes | 
|---|---|---|---|---|---|
| CVE-2015-3113 | Adobe Flash Player Heap-Based Buffer Overflow Vulnerability | secondary_impact | T1622 | Debugger Evasion | Comments This heap-based buffer overflow vulnerability is exploited by having a user open a maliciously-crafted file. 
In the wild, this exploitation has been used in order to establish command and control (over HTTP) with a target system.  The command and control functionality has also been seen to employ debugging/sandboxing evasion. References | 
| CVE-2015-3113 | Adobe Flash Player Heap-Based Buffer Overflow Vulnerability | secondary_impact | T1497 | Virtualization/Sandbox Evasion | Comments This heap-based buffer overflow vulnerability is exploited by having a user open a maliciously-crafted file. 
In the wild, this exploitation has been used in order to establish command and control (over HTTP) with a target system.  The command and control functionality has also been seen to employ debugging/sandboxing evasion. References | 
| CVE-2015-3113 | Adobe Flash Player Heap-Based Buffer Overflow Vulnerability | primary_impact | T1071.001 | Web Protocols | Comments This heap-based buffer overflow vulnerability is exploited by having a user open a maliciously-crafted file. 
In the wild, this exploitation has been used in order to establish command and control (over HTTP) with a target system.  The command and control functionality has also been seen to employ debugging/sandboxing evasion. References | 
| CVE-2015-3113 | Adobe Flash Player Heap-Based Buffer Overflow Vulnerability | exploitation_technique | T1204.002 | Malicious File | Comments This heap-based buffer overflow vulnerability is exploited by having a user open a maliciously-crafted file. 
In the wild, this exploitation has been used in order to establish command and control (over HTTP) with a target system.  The command and control functionality has also been seen to employ debugging/sandboxing evasion. References |