Junglewise Threat Intelligence

CVE-2018-4878: Adobe Flash Player Use-After-Free Vulnerability

CVE-2018-4878 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Adobe Flash Player. Vendors: Adobe.

Executive brief

Adobe Flash Player contains a use-after-free vulnerability in the Primetime SDK due to a dangling pointer related to media player listener objects. A successful attack can lead to arbitrary code execution when a user interacts with malicious content.

Affected products

  • Adobe Flash Player before 28.0.0.161

Timeline

  • 2018-01: exploited: Exploited in the wild in January and February 2018.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats