CVE-2018-5007: Incorrect Type Cast
Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Other sources
Adobe Security Bulletin APSB18-24 for Adobe Flash Player describes a flaw that can possibly lead to arbitrary code execution when Flash Player is used to play a specially crafted SWF file:
Type Confusion -- CVE-2018-5007
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-24.html
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-5007.
What is the severity of CVE-2018-5007?
The severity of CVE-2018-5007 is high.
What is the affected software of CVE-2018-5007?
The affected software of CVE-2018-5007 is Adobe Flash Player 30.0.0.113 and earlier versions.
What is the potential impact of CVE-2018-5007?
Successful exploitation of CVE-2018-5007 could lead to arbitrary code execution in the context of the current user.
How can I fix CVE-2018-5007?
To fix CVE-2018-5007, update Adobe Flash Player to version 30.0.0.134 or later.