CVE-2018-15967
published 2018-09-25CVE-2018-15967: Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to information disclosure.
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
7.60%
93.9th percentile
Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to information disclosure.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 31.0.0.108 | — |
| adobe | flash_player | — | — |
| adobe | flash_player_desktop_runtime | <= 31.0.0.108 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5fr3-pj37-r3jj: Adobe Flash Player versions 30
ghsa_unreviewed·2022-05-13
CVE-2018-15967 [HIGH] CWE-200 GHSA-5fr3-pj37-r3jj: Adobe Flash Player versions 30
Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to information disclosure.
Red Hat
flash-plugin: Information Disclosure vulnerability (APSB18-31)
vendor_redhat·2018-09-11·CVSS 7.5
CVE-2018-15967 [HIGH] CWE-200 flash-plugin: Information Disclosure vulnerability (APSB18-31)
flash-plugin: Information Disclosure vulnerability (APSB18-31)
Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to information disclosure.
No detection rules found.
No public exploits indexed.
Qualys
September 2018 Patch Tuesday – 61 Vulns, FragmentSmack, Hyper-V Escape
blogs_qualys·2018-09-11·CVSS 7.5
CVE-2018-8475 [HIGH] September 2018 Patch Tuesday – 61 Vulns, FragmentSmack, Hyper-V Escape
In this month’s Patch Tuesday release there are 61 vulnerabilities patched with 17 Criticals. Out of the criticals, most are browser-related, with the rest including Windows, Hyper-V, and .net Framework. A vulnerability ( CVE-2018-8475 ) in Windows’ image parsing has been publicly disclosed, in addition to a vulnerability ( CVE-2018-8457 ) in the Scripting Engine.
## Workstation Patches
Browser and Scripting Engine patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. The PDF viewer, Windows image parsing, .net Framework, and Windows font library also have patches available that require a user to interact with a malicious site or file. With two of these vulnerabilities being publicly disclosed, it is
Krebs
Patch Tuesday, September 2018 Edition
blogs_krebs·2018-09-11·CVSS 7.5
[HIGH] Patch Tuesday, September 2018 Edition
Adobe and Microsoft today each released patches to fix serious security holes in their software. Adobe pushed out a new version of its beleaguered Flash Player browser plugin. Redmond issued updates to address at least 61 distinct vulnerabilities in Microsoft Windows and related programs, including several flaws that were publicly detailed prior to today and one “zero-day” bug in Windows that is already being actively exploited by attackers.
As per usual, the bulk of the fixes from Microsoft tackle security weaknesses in the company’s Web browsers, Internet Explorer and Edge . Patches also are available for Windows, Office , Sharepoint , and the .NET Framework , among other components.
Of the 61 bugs fixed in this patch batch, 17 earned Microsoft’s “critical” rating, meaning malware or m
Krebs
Patch Tuesday, September 2018 Edition
blogs_krebs·2018-09-11·CVSS 7.5
[HIGH] Patch Tuesday, September 2018 Edition
Adobe and Microsoft today each released patches to fix serious security holes in their software. Adobe pushed out a new version of its beleaguered Flash Player browser plugin. Redmond issued updates to address at least 61 distinct vulnerabilities in Microsoft Windows and related programs, including several flaws that were publicly detailed prior to today and one “zero-day” bug in Windows that is already being actively exploited by attackers.
Of the 61 bugs fixed in this patch batch, 17 earned Microsoft’s “critical” rating, meaning malware or miscreants could use them to break into Windows computers with little or no help from users.
The zero-day flaw, CVE-2018-8440, affects Microsoft operating systems from Windows 7 through Windows 10 and allows a program launched by a restricted Windows
Qualys
Sept 2018 Patch Tuesday | Qualys
blogs_qualys·2018-09-11·CVSS 7.5
CVE-2018-8475 [HIGH] Sept 2018 Patch Tuesday | Qualys
In this month’s Patch Tuesday release there are 61 vulnerabilities patched with 17 Criticals. Out of the criticals, most are browser-related, with the rest including Windows, Hyper-V, and .net Framework. A vulnerability (CVE-2018-8475) in Windows’ image parsing has been publicly disclosed, in addition to a vulnerability (CVE-2018-8457) in the Scripting Engine.
### Workstation Patches
Browser and Scripting Engine patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. The PDF viewer, Windows image parsing, .net Framework, and Windows font library also have patches available that require a user to interact with a malicious site or file. With two of these vulnerabilities being publicly disclosed, it is im
Bugzilla
CVE-2018-15967 flash-plugin: Information Disclosure vulnerability (APSB18-31)
bugzilla·2018-09-11·CVSS 7.5
CVE-2018-15967 [HIGH] CVE-2018-15967 flash-plugin: Information Disclosure vulnerability (APSB18-31)
CVE-2018-15967 flash-plugin: Information Disclosure vulnerability (APSB18-31)
Adobe Security Bulletin APSB18-31 for Adobe Flash Player describes a flaw that can possibly lead to information disclosure when Flash Player is used to play a specially crafted SWF file:
Privilege Escalation -- CVE-2018-15967
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-31.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:2707 https://access.redhat.com/errata/RHSA-2018:2707
http://www.securityfocus.com/bid/105315http://www.securitytracker.com/id/1041620https://access.redhat.com/errata/RHSA-2018:2707https://helpx.adobe.com/security/products/flash-player/apsb18-31.htmlhttp://www.securityfocus.com/bid/105315http://www.securitytracker.com/id/1041620https://access.redhat.com/errata/RHSA-2018:2707https://helpx.adobe.com/security/products/flash-player/apsb18-31.html
2018-09-25
Published