CVE-2018-15982: Adobe Flash Player Use-After-Free Vulnerability

Published Dec 5, 2018
·
Updated

Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability

Other sources

Adobe Security Bulletin APSB18-42 for Adobe Flash Player describes a flaw that can possibly lead to arbitrary code execution when Flash Player is used to play a specially crafted SWF file:

Use after free -- CVE-2018-15982

External References:

https://helpx.adobe.com/security/products/flash-player/apsb18-42.html

Red Hat

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

NVD

Affected Software

29 affected componentsFixes available
redhat/flash-plugin<32.0.0.101
32.0.0.101
Adobe Flash Player
Adobe Flash Player<=31.0.0.153
Apple iOS and macOS
Linux Linux kernel
Microsoft Windows
Adobe Flash Player Chrome<=31.0.0.153
Google Chrome OS
Adobe Flash Player Edge<=31.0.0.153
Adobe Flash Player Internet Explorer 11<=31.0.0.153
Microsoft Windows 10
Microsoft Windows 8.1
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Workstation=6.0
Adobe Flash Player Installer<=31.0.0.108
All of the following
Adobe Flash Player<=31.0.0.153
Any of the following
Linux Linux kernel
Microsoft Windows
All of the following
Adobe Flash Player Chrome<=31.0.0.153
Any of the following
Google Chrome OS
Linux Linux kernel
Microsoft Windows
All of the following
Any of the following
Adobe Flash Player Edge<=31.0.0.153
Adobe Flash Player Internet Explorer 11<=31.0.0.153
Any of the following
Microsoft Windows 10
Microsoft Windows 8.1
All of the following
Adobe Flash Player Installer<=31.0.0.108
Microsoft Windows

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/flash-plugin to a version that resolves this vulnerability.

    Fixed in 32.0.0.101
  2. Remove

    Remove Adobe Flash Player from your environment.

    If still in use, disconnect/remove the end-of-life Adobe Flash Player from the environment.

Event History

Jan 18, 2019
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 15, 2022
Known Exploited
via CISA·12:00 AM
Known Ransomware
via CISA·12:00 AM
Sep 18, 58448
Event
via NVD·11:22 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2018-15982?

CVE-2018-15982 is a use-after-free vulnerability in Adobe Flash Player.

2

How severe is CVE-2018-15982?

CVE-2018-15982 has a severity rating of 9.8 out of 10, classified as critical.

3

Is Adobe Flash Player affected by CVE-2018-15982?

Yes, Adobe Flash Player versions 31.0.0.153 and earlier, as well as 31.0.0.108 and earlier, are affected by CVE-2018-15982.

4

What is the potential impact of exploiting CVE-2018-15982?

Successful exploitation of CVE-2018-15982 could lead to arbitrary code execution.

5

How can I fix CVE-2018-15982?

To fix CVE-2018-15982, update Adobe Flash Player to version 32.0.0.101 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203