First published: Mon Feb 05 2018(Updated: )
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player's quality of service functionality. A successful attack can lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | <28.0.0.161 | |
macOS | ||
Linux Kernel | ||
Microsoft Windows Operating System | ||
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Macromedia Flash Player | <28.0.0.161 | |
Macromedia Flash Player | <28.0.0.161 | |
Windows 10 | ||
Microsoft Windows | ||
Macromedia Flash Player | <28.0.0.161 | |
Chrome OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-4877 is a use-after-free vulnerability in Adobe Flash Player before 28.0.0.161.
The vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player's quality of service functionality.
A successful attack can lead to arbitrary code execution.
Adobe Flash Player versions before 28.0.0.161 are affected.
CVE-2018-4877 has a severity rating of 9.8 (Critical).