CVE-2018-4919: Use After Free
Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable use after free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Other sources
Adobe Security Bulletin APSB18-05 for Adobe Flash Player describes a use after free flaw that can possibly lead to remote code execution when Flash Player is used to play a specially crafted SWF file.
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-05.html
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-4919?
CVE-2018-4919 is a use after free vulnerability in Adobe Flash Player versions 28.0.0.161 and earlier.
What is the severity of CVE-2018-4919?
The severity of CVE-2018-4919 is critical with a severity score of 8.8.
How can CVE-2018-4919 be exploited?
Successful exploitation of CVE-2018-4919 could lead to arbitrary code execution in the context of the current user.
How do I fix CVE-2018-4919?
To fix CVE-2018-4919, update Adobe Flash Player to version 29.0.0.113 or later.
Where can I find more information about CVE-2018-4919?
You can find more information about CVE-2018-4919 at the following references: [1] [2] [3]