cbcvebase.
CVE-2018-15982
published 2019-01-18

CVE-2018-15982: Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary…

PriorityP190high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-08-15
Exploited in the wild
EPSS
81.97%
99.6th percentile
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Affected

5 ranges
VendorProductVersion rangeFixed in
adobeflash_player<= 31.0.0.153
adobeflash_player_installer<= 31.0.0.108
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_workstation

Detection & IOCsextracted from sources · hover to see the quote

othermaliciously crafted RAR file
  • Delivery vector is a spear-phishing document (RAR file containing malicious Flash content) disguised as an employee survey; monitor for RAR archives delivered via email that contain SWF or Flash-related content.
  • Post-exploitation payload masquerades as an Nvidia driver application; hunt for unexpected Nvidia-named executables dropped or executed from non-standard paths (e.g., temp directories, user profile folders).
  • CVE-2018-15982 was integrated into the Spelevo Exploit Kit and used to distribute Maze ransomware; monitor for drive-by exploit kit traffic patterns associated with SpelevoEKFlashContainer AutoFocus tag.
  • CVE-2018-15982 was exploited in a targeted spear-phishing attack against Polyclinic No. 2 affiliated with the Presidential Administration of Russia; the attack chain involved a Chrome extension lure in addition to the survey document.
  • ·Affected versions are Adobe Flash Player 31.0.0.153 and earlier, and 31.0.0.108 and earlier; the fixed version is 32.0.0.101. Ensure Flash is updated to 32.0.0.101 or later across all browsers (standalone, Chrome, Edge, IE11).
  • ·Adobe Flash Player installed with Google Chrome, Microsoft Edge, and Internet Explorer 11 (Windows 10/8.1) will be automatically updated to 32.0.0.101; standalone Desktop Runtime users must manually trigger the update unless 'Allow Adobe to install updates' is enabled.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.