CyberSec.Space Logo
CVEブラウザに戻る

CVE-2018-4878

Known Exploited (CISA KEV)HIGH
7.8
CVSS Severity Score
EPSS Score52.6350%
EPSS Percentile91.64th
Published2018年2月6日
Last Modified2025年11月18日

Vulnerability Description

A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.

Affected Platforms (CPE)

📦
Adobe

Flash Player

< 28.0.0.161
💻
Redhat

Enterprise Linux Desktop

= 6.0
💻
Redhat

Enterprise Linux Server

= 6.0
💻
Redhat

Enterprise Linux Workstation

= 6.0
📦
Adobe

Flash Player

< 28.0.0.161
📦
Adobe

Flash Player

< 28.0.0.161
📦
Adobe

Flash Player

< 28.0.0.161

References & Advisories

関連する脆弱性情報