CVE-2018-4878
HIGHA use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player…
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
Affected Products
flash playeradobeenterprise linux desktopredhatenterprise linux serverredhatenterprise linux workstationredhatResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Flash ActiveX 28.0.0.137 - Code Execution (2)
by smgorelik · Feb 13, 2016
Adobe Flash < 28.0.0.161 - Use-After-Free
by SyFi · Apr 6, 2018
Flash ActiveX 28.0.0.137 - Code Execution (1)
by smgorelik · Feb 16, 2016
Frequently Asked Questions
Is CVE-2018-4878 in your stack?
O3 detects CVE-2018-4878 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.