⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: The impacted product is end-of-life and should be disconnected if still in use.. Due date: 2022-08-15.

CVE-2018-15982Use After Free in Adobe Flash Player

CWE-416Use After Free42 documents19 sources
Severity
7.8HIGHNVD
EPSS
93.6%
top 0.16%
CISA KEV
KEVRansomware
Added 2022-02-15
Due 2022-08-15
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJan 18
KEV addedFeb 15
KEV dueAug 15
Latest updateMar 2
CISA Required Action: The impacted product is end-of-life and should be disconnected if still in use.

Description

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Patches

🔴Vulnerability Details

4
GHSA
GHSA-26v8-ffh8-7vqg: Flash Player versions 312022-05-14
OSV
CVE-2018-15982: Flash Player versions 312019-01-18
CVEList
CVE-2018-15982: Flash Player versions 312019-01-18
VulnCheck
Adobe Flash Player Use-After-Free Vulnerability2018

💥Exploits & PoCs

1
Exploit-DB
Adobe Flash ActiveX Plugin 28.0.0.137 - Remote Code Execution (PoC)2018-12-24

🔍Detection Rules

1
Suricata
ET EXPLOIT Possible Inbound Flash Exploit (CVE-2018-15982)2019-08-02

📋Vendor Advisories

2
CISA
Adobe Flash Player Use-After-Free Vulnerability2022-02-15
Red Hat
flash-plugin: Arbitrary Code Execution vulnerability (APSB18-42)2018-12-05

🕵️Threat Intelligence

31
Trendmicro
Leveraging Data Science to Minimize the Blast Radius of Ransomware Attacks2023-03-02
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys2022-02-23
Sentinelone
Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone2020-11-26
Sentinelone
Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone - SentinelLabs2020-11-25
Unit42
Threat Brief: Maze Ransomware2020-05-08

📄Research Papers

1
arXiv
Technical Report -- Expected Exploitability: Predicting the Development of Functional Vulnerability Exploits2022-02-03

💬Community

1
Bugzilla
CVE-2018-15982 flash-plugin: Arbitrary Code Execution vulnerability (APSB18-42)2018-12-05
CVE-2018-15982 — Use After Free in Adobe Flash Player | cvebase