CVE-2018-12828Improper Privilege Management in Adobe Flash Player

6 documents6 sources
Severity
9.8CRITICALNVD
EPSS
1.5%
top 19.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 29
Latest updateMay 13

Description

Adobe Flash Player 30.0.0.134 and earlier have a "use of a component with a known vulnerability" vulnerability. Successful exploitation could lead to privilege escalation.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Patches

🔴Vulnerability Details

3
GHSA
GHSA-fc65-rmq4-2hch: Adobe Flash Player 302022-05-13
CVEList
CVE-2018-12828: Adobe Flash Player 302018-08-29
OSV
CVE-2018-12828: Adobe Flash Player 302018-08-29

📋Vendor Advisories

1
Red Hat
flash-plugin: Privilege Escalation vulnerability (APSB18-25)2018-08-14

💬Community

1
Bugzilla
CVE-2018-12828 flash-plugin: Privilege Escalation vulnerability (APSB18-25)2018-08-14
CVE-2018-12828 — Improper Privilege Management in Adobe | cvebase