CVE-2018-15983
published 2019-01-18CVE-2018-15983: Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful…
PriorityP337high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
3.28%
87.1th percentile
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 31.0.0.153 | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: Privilege Escalation vulnerability (APSB18-42)
vendor_redhat·2018-12-05·CVSS 7.8
CVE-2018-15983 [HIGH] CWE-426 flash-plugin: Privilege Escalation vulnerability (APSB18-42)
flash-plugin: Privilege Escalation vulnerability (APSB18-42)
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
Package: flash-plugin (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-c2xf-g8c5-v9p9: Flash Player versions 31
ghsa_unreviewed·2022-05-14
CVE-2018-15983 [HIGH] CWE-426 GHSA-c2xf-g8c5-v9p9: Flash Player versions 31
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
OSV
CVE-2018-15983: Flash Player versions 31
osv·2019-01-18·CVSS 7.8
CVE-2018-15983 [HIGH] CVE-2018-15983: Flash Player versions 31
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
No detection rules found.
No public exploits indexed.
Qualys
December 2018 Patch Tuesday – 39 Vulns, Workstation Patches, Adobe Vulns
blogs_qualys·2018-12-11·CVSS 7.8
[HIGH] December 2018 Patch Tuesday – 39 Vulns, Workstation Patches, Adobe Vulns
This month’s Patch Tuesday addresses 39 vulnerabilities, with 9 of them labeled as Critical. Out of the Criticals, most are browser-related, with the rest including Windows, and .net Framework. A Privilege Escalation vulnerability exists in Windows kernel which has been exploited in wild. Adobe also patched 9 Critical and Important vulnerabilities this month for Adobe Acrobat and Reader.
On the basis of volume and severity this Patch Tuesday is light in weight.
## Workstation Patches
Browser and Scripting Engine patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users. Out of the 9 vulnerabilities, 6 can be exploited through br
Qualys
December 2018 Patch Tuesday – 39 Vulns, Workstation Patches, Adobe Vulns | Qualys
blogs_qualys·2018-12-11·CVSS 7.8
[HIGH] December 2018 Patch Tuesday – 39 Vulns, Workstation Patches, Adobe Vulns | Qualys
This month’s Patch Tuesday addresses 39 vulnerabilities, with 9 of them labeled as Critical. Out of the Criticals, most are browser-related, with the rest including Windows, and .net Framework. A Privilege Escalation vulnerability exists in Windows kernel which has been exploited in wild. Adobe also patched 9 Critical and Important vulnerabilities this month for Adobe Acrobat and Reader.
On the basis of volume and severity this Patch Tuesday is light in weight.
### Workstation Patches
Browser and Scripting Engine patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users. Out of the 9 vulnerabilities, 6 can be exploited through b
Bugzilla
CVE-2018-15983 flash-plugin: Privilege Escalation vulnerability (APSB18-42)
bugzilla·2018-12-05·CVSS 7.8
CVE-2018-15983 [HIGH] CVE-2018-15983 flash-plugin: Privilege Escalation vulnerability (APSB18-42)
CVE-2018-15983 flash-plugin: Privilege Escalation vulnerability (APSB18-42)
Adobe Security Bulletin APSB18-42 for Adobe Flash Player describes a flaw that can possibly lead to privilege escalation when Flash Player is used to play a specially crafted SWF file:
Insecure Library Loading (DLL hijacking) -- CVE-2018-15983
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-42.html
Discussion:
DLL hijacking would not be applicable to the Linux versions of Adobe Flash Player.
2019-01-18
Published