CVE-2018-4878
גבוהה 7.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Adobe Flash Player Use-After-Free Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- The impacted product is end-of-life and should be disconnected if still in use.
תיאור (מקור, אנגלית)
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 90% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-416
מוצרים מושפעים
adobe: flash player; apple: macos; linux: linux kernel; microsoft: windows; redhat: enterprise linux desktop; redhat: enterprise linux server; redhat: enterprise linux workstation; microsoft: windows 10; microsoft: windows 8.1; google: chrome os
קישורים
- https://helpx.adobe.com/security/products/flash-player/apsb18-03.html Vendor Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb18-03.html Vendor Advisory
- https://securingtomorrow.mcafee.com/mcafee-labs/hackers-bypassed-adobe-flash-p… ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/44412/ ExploitThird Party AdvisoryVDB Entry
- https://securingtomorrow.mcafee.com/mcafee-labs/hackers-bypassed-adobe-flash-p… ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/44412/ ExploitThird Party AdvisoryVDB Entry
- http://blog.talosintelligence.com/2018/02/group-123-goes-wild.html Technical DescriptionThird Party Advisory
- http://www.securityfocus.com/bid/102893 Broken Link
- http://www.securitytracker.com/id/1040318 Broken Link
- https://access.redhat.com/errata/RHSA-2018:0285 Third Party Advisory