CVE-2018-4878: Adobe Flash Player Use-After-Free Vulnerability
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
Other sources
Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disconnect Adobe Flash Player if it is still in use, since the impacted product is end-of-life.
Event History
Frequently Asked Questions
What is CVE-2018-4878?
CVE-2018-4878 is a use-after-free vulnerability in Adobe Flash Player before version 28.0.0.161.
How does CVE-2018-4878 occur?
CVE-2018-4878 occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects.
What is the severity of CVE-2018-4878?
The severity of CVE-2018-4878 is critical with a CVSS score of 9.8.
How can CVE-2018-4878 be exploited?
CVE-2018-4878 can be exploited to execute arbitrary code.
How can I fix CVE-2018-4878?
To fix CVE-2018-4878, update Adobe Flash Player to version 28.0.0.161 or later.