CVE-2018-12828: Critical severity macromedia flash player vulnerability
Adobe Flash Player 30.0.0.134 and earlier have a "use of a component with a known vulnerability" vulnerability. Successful exploitation could lead to privilege escalation.
Other sources
Adobe Security Bulletin APSB18-25 for Adobe Flash Player describes a flaw that can possibly lead to privilege escalation when Flash Player is used to play a specially crafted SWF file:
Use of a component with a known vulnerability -- CVE-2018-12828
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-25.html
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2018-12828.
What is the severity of CVE-2018-12828?
The severity of CVE-2018-12828 is critical.
What is the affected software for CVE-2018-12828?
The affected software for CVE-2018-12828 includes Adobe Flash Player versions 30.0.0.134 and earlier.
What is the remedy for CVE-2018-12828?
The remedy for CVE-2018-12828 is to update Adobe Flash Player to version 30.0.0.154 or later.
Where can I find more information about CVE-2018-12828?
You can find more information about CVE-2018-12828 at the following references: - [http://www.securityfocus.com/bid/105071](http://www.securityfocus.com/bid/105071) - [http://www.securitytracker.com/id/1041448](http://www.securitytracker.com/id/1041448) - [https://access.redhat.com/errata/RHSA-2018:2435](https://access.redhat.com/errata/RHSA-2018:2435)