⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: The impacted product is end-of-life and should be disconnected if still in use.. Due date: 2022-08-15.
CVE-2018-15982 — Use After Free in Adobe Flash Player
Severity
7.8HIGHNVD
EPSS
93.6%
top 0.16%
CISA KEV
KEVRansomware
Added 2022-02-15
Due 2022-08-15
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedJan 18
KEV addedFeb 15
KEV dueAug 15
Latest updateMar 2
CISA Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Description
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages5 packages
Patches
🔴Vulnerability Details
4💥Exploits & PoCs
1🔍Detection Rules
1📋Vendor Advisories
2🕵️Threat Intelligence
31Sentinelone
▶
📄Research Papers
1arXiv▶
Technical Report -- Expected Exploitability: Predicting the Development of Functional Vulnerability Exploits↗2022-02-03