First published: Tue May 08 2018(Updated: )
Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/flash-plugin | <29.0.0.171 | 29.0.0.171 |
Adobe Acrobat Reader | <=29.0.0.140 | |
Apple iOS and macOS | ||
Linux Kernel | ||
Microsoft Windows | ||
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux workstation | =6.0 | |
Adobe Acrobat Reader | <=29.0.0.140 | |
Adobe Acrobat Reader | <=29.0.0.140 | |
Microsoft Windows 10 | ||
Microsoft Windows 8.1 | ||
Adobe Acrobat Reader | <=29.0.0.140 | |
Chrome OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-4944.
The severity of CVE-2018-4944 is critical with a CVSS score of 9.8.
The affected software is Adobe Flash Player versions 29.0.0.140 and earlier.
The remedy for CVE-2018-4944 is to update to version 29.0.0.171 of Adobe Flash Player.
The references for CVE-2018-4944 are: http://www.securityfocus.com/bid/104101, http://www.securitytracker.com/id/1040840, https://access.redhat.com/errata/RHSA-2018:1367.