Junglewise Threat Intelligence

CVE-2018-5002: Adobe Flash Player Stack-based Buffer Overflow Vulnerability

CVE-2018-5002 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-05-23

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Flash Player contains a stack-based buffer overflow vulnerability (CWE-121) due to improper bounds checking. Successful exploitation allows a remote attacker to execute arbitrary code in the context of the current user.

Affected products

  • Adobe Flash Player 29.0.0.171 and earlier

Timeline

  • 2018-06-07: advisory: Adobe APSB18-19 advisory published
  • 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-23: disclosed: NVD publication date
  • 2022-06-13: other: CISA due date for remediation (disconnect EOL product)

Related threats