Executive brief
Adobe Flash Player contains a use-after-free vulnerability in the Primetime SDK due to a dangling pointer related to media player listener objects. A successful attack can lead to arbitrary code execution when a user interacts with malicious content.
Affected products
- Adobe Flash Player before 28.0.0.161
Timeline
- 2018-01: exploited: Exploited in the wild in January and February 2018.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.