Junglewise Threat Intelligence

CVE-2018-15982: Adobe Flash Player Use-After-Free Vulnerability

CVE-2018-15982 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-02-15

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Flash Player contains a use-after-free vulnerability in the com.adobe.tvsdk.mediacore.metadata component. Successful exploitation allows for arbitrary code execution on the affected system.

Affected products

  • Adobe Systems Incorporated Flash Player 31.0.0.153 and earlier
  • Adobe Systems Incorporated Flash Player Installer 31.0.0.108 and earlier

Timeline

  • 2018-12-05: advisory: Adobe released security bulletin APSB18-42 regarding this vulnerability.
  • 2019-01-29: disclosed: Initial analysis by NIST.
  • 2022-02-15: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats