First published: Tue Feb 06 2018(Updated: )
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player | <28.0.0.161 | |
Apple macOS | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Redhat Enterprise Linux Desktop | =6.0 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Workstation | =6.0 | |
Adobe Flash Player | <28.0.0.161 | |
Adobe Flash Player | <28.0.0.161 | |
Microsoft Windows 10 | ||
Microsoft Windows 8.1 | ||
Adobe Flash Player | <28.0.0.161 | |
Google Chrome OS | ||
Adobe Flash Player | ||
All of | ||
Any of | ||
Apple macOS | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Adobe Flash Player | <28.0.0.161 | |
All of | ||
Any of | ||
Microsoft Windows 10 | ||
Microsoft Windows 8.1 | ||
Any of | ||
Adobe Flash Player | <28.0.0.161 | |
Adobe Flash Player | <28.0.0.161 | |
All of | ||
Any of | ||
Apple macOS | ||
Google Chrome OS | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Adobe Flash Player | <28.0.0.161 |
The impacted product is end-of-life and should be disconnected if still in use.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-4878 is a use-after-free vulnerability in Adobe Flash Player before version 28.0.0.161.
CVE-2018-4878 occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects.
The severity of CVE-2018-4878 is critical with a CVSS score of 9.8.
CVE-2018-4878 can be exploited to execute arbitrary code.
To fix CVE-2018-4878, update Adobe Flash Player to version 28.0.0.161 or later.