Executive brief
Adobe Flash Player contains a use-after-free vulnerability in the com.adobe.tvsdk.mediacore.metadata component. Successful exploitation allows for arbitrary code execution on the affected system.
Affected products
- Adobe Systems Incorporated Flash Player 31.0.0.153 and earlier
- Adobe Systems Incorporated Flash Player Installer 31.0.0.108 and earlier
Timeline
- 2018-12-05: advisory: Adobe released security bulletin APSB18-42 regarding this vulnerability.
- 2019-01-29: disclosed: Initial analysis by NIST.
- 2022-02-15: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.