CVE-2018-4944: Incorrect Type Cast
Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Other sources
Adobe Security Bulletin APSB18-16 for Adobe Flash Player describes a flaw that can possibly lead to arbitrary code execution when Flash Player is used to play a specially crafted SWF file:
Type Confusion -- CVE-2018-4944
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-16.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Adobe Flash Player vulnerability?
The vulnerability ID is CVE-2018-4944.
What is the severity of CVE-2018-4944?
The severity of CVE-2018-4944 is critical with a CVSS score of 9.8.
What is the affected software for CVE-2018-4944?
The affected software is Adobe Flash Player versions 29.0.0.140 and earlier.
What is the remedy for CVE-2018-4944?
The remedy for CVE-2018-4944 is to update to version 29.0.0.171 of Adobe Flash Player.
What is the reference for CVE-2018-4944?
The references for CVE-2018-4944 are: http://www.securityfocus.com/bid/104101, http://www.securitytracker.com/id/1040840, https://access.redhat.com/errata/RHSA-2018:1367.