• News/
  • https://threatpost.com/adobe-flash-player-zero-day-spotted-in-the-wild/129742/

Adobe Flash Player Zero-Day Spotted in the Wild

Threatpost
·
Published Feb 1, 2018
·
Updated

The South Korean Computer Emergency Response Team issued a warning Wednesday of a new Adobe Flash Player zero-day spotted in the wild. The security bulletin warns that the attacks are focused on South Koreans and involve malicious Microsoft Word documents. According to the South Korean Computer Emergency Response Team (KR-CERT), the zero-day is believed to be a Flash SWF file embedded in MS Word documents. Impacted is Adobe’s most recent Flash Player 28.0.0.137 and earlier. “An attacker may be able to convince a user to open a Microsoft Office document, web page, or spam mail containing a Flash file,” according to a machine translation of the KR-CERT security bulletin. Adobe released a security advisory on Thursday acknowledging the vulnerability and attacks. Adobe said the zero-day is exploiting the vulnerability CVE-2018-4878, a critical remote code execution bug. According to Adobe it was discovered in Adobe Flash Player before 28.0.0.137. Adobe credits KR-CERT for reporting this issue. Adobe said affected products are versions of Adobe Flash Player Desktop Runtime (Win/Mac), Adobe Flash Player for Google Chrome (Win/Mac/Linux/Chrome OS), Adobe Flash Player for Microsoft Edge and Internet Explorer 11 (Win 10 & 8.1) and Adobe Flash Player Desktop Runtime (Linux). A complete list is available here. Simon Choi, a security researcher with the South Korean security firm Hauri, claimed on Twitter that the zero-day vulnerability originated in North Korea and has been in use since...

Read full article

Affected Software

4 affected components
Adobe Flash Player Desktop Runtime (Win/Mac)<=28.0.0.137
Adobe Flash Player for Google Chrome<=28.0.0.137
Adobe Flash Player for Microsoft Edge and Internet Explorer 11<=28.0.0.137
Adobe Flash Player Desktop Runtime (Linux)<=28.0.0.137
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a newly discovered zero-day vulnerability in Adobe Flash Player that is actively being exploited, particularly targeting users in South Korea.

2

What security implications are discussed in the article?

The security implications include the risk of attackers using malicious Microsoft Word documents to exploit the zero-day vulnerability.

3

What products or software are affected by the zero-day vulnerability?

The affected products include Adobe Flash Player Desktop Runtime for Win/Mac, Google Chrome, Microsoft Edge, Internet Explorer 11, and Linux.

4

Which organization issued the warning about the zero-day vulnerability?

The warning was issued by the South Korean Computer Emergency Response Team.

5

What type of attacks are being conducted with this vulnerability?

The attacks involve hacking attempts that utilize malicious Word documents to exploit the zero-day in Adobe Flash Player.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203