CVE-2018-4920: Critical severity adobe flash player vulnerability
Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Other sources
Adobe Security Bulletin APSB18-05 for Adobe Flash Player describes a type confusion flaw that can possibly lead to remote code execution when Flash Player is used to play a specially crafted SWF file.
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-05.html
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-4920?
CVE-2018-4920 is a vulnerability in Adobe Flash Player versions 28.0.0.161 and earlier that could lead to arbitrary code execution.
How severe is the vulnerability CVE-2018-4920?
The severity of CVE-2018-4920 is critical with a CVSS score of 8.8.
Which software versions are affected by vulnerability CVE-2018-4920?
Adobe Flash Player versions 28.0.0.161 and earlier are affected by vulnerability CVE-2018-4920.
How can I fix vulnerability CVE-2018-4920?
To fix vulnerability CVE-2018-4920, you should update Adobe Flash Player to version 29.0.0.113 or later.
Where can I find more information about vulnerability CVE-2018-4920?
You can find more information about vulnerability CVE-2018-4920 on SecurityFocus, SecurityTracker, and the Red Hat advisory RHSA-2018:0520.