First published: Tue Mar 13 2018(Updated: )
Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/flash-plugin | <29.0.0.113 | 29.0.0.113 |
Adobe Flash Player Desktop Runtime | <=28.0.0.161 | |
Apple Mac OS X | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Adobe Flash Player | <=28.0.0.161 | |
Google Chrome OS | ||
Adobe Flash Player | <=28.0.0.161 | |
Adobe Flash Player | <=28.0.0.161 | |
Microsoft Windows 10 | ||
Microsoft Windows 8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-4920 is a vulnerability in Adobe Flash Player versions 28.0.0.161 and earlier that could lead to arbitrary code execution.
The severity of CVE-2018-4920 is critical with a CVSS score of 8.8.
Adobe Flash Player versions 28.0.0.161 and earlier are affected by vulnerability CVE-2018-4920.
To fix vulnerability CVE-2018-4920, you should update Adobe Flash Player to version 29.0.0.113 or later.
You can find more information about vulnerability CVE-2018-4920 on SecurityFocus, SecurityTracker, and the Red Hat advisory RHSA-2018:0520.