CVE-2018-4877: Use After Free
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player's quality of service functionality. A successful attack can lead to arbitrary code execution.
Other sources
Adobe Security Advisory APSA18-01 for Adobe Flash Player describes an use-after-free flaw that can possibly lead to code exeucution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSA18-01:
Use-after-free Remote Code Execution Critical CVE-2018-4878
Reference:
https://helpx.adobe.com/security/products/flash-player/apsa18-01.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-4877?
CVE-2018-4877 is a use-after-free vulnerability in Adobe Flash Player before 28.0.0.161.
How does the CVE-2018-4877 vulnerability occur?
The vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player's quality of service functionality.
What is the impact of CVE-2018-4877?
A successful attack can lead to arbitrary code execution.
Which software versions are affected by CVE-2018-4877?
Adobe Flash Player versions before 28.0.0.161 are affected.
How severe is CVE-2018-4877?
CVE-2018-4877 has a severity rating of 9.8 (Critical).