CVE-2018-4877
published 2018-02-06CVE-2018-4877: A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK…
PriorityP348critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
8.51%
94.4th percentile
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player's quality of service functionality. A successful attack can lead to arbitrary code execution.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | < 28.0.0.161 | 28.0.0.161 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hcf8-mxwr-h337: A use-after-free vulnerability was discovered in Adobe Flash Player before 28
ghsa_unreviewed·2022-05-13
CVE-2018-4877 [CRITICAL] CWE-416 GHSA-hcf8-mxwr-h337: A use-after-free vulnerability was discovered in Adobe Flash Player before 28
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player's quality of service functionality. A successful attack can lead to arbitrary code execution.
OSV
CVE-2018-4877: A use-after-free vulnerability was discovered in Adobe Flash Player before 28
osv·2018-02-06·CVSS 9.8
CVE-2018-4877 [CRITICAL] CVE-2018-4877: A use-after-free vulnerability was discovered in Adobe Flash Player before 28
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player's quality of service functionality. A successful attack can lead to arbitrary code execution.
Red Hat
flash-plugin: use-after-free causing remote code execution (APSB18-03)
vendor_redhat·2018-02-01·CVSS 9.8
CVE-2018-4877 [CRITICAL] CWE-416 flash-plugin: use-after-free causing remote code execution (APSB18-03)
flash-plugin: use-after-free causing remote code execution (APSB18-03)
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player's quality of service functionality. A successful attack can lead to arbitrary code execution.
No detection rules found.
No public exploits indexed.
Tenable
Adobe Flash Player Has (Another) Critical Zero-Day Vulnerability
blogs_tenable·2018-06-07·CVSS 9.8
CVE-2018-5002 [CRITICAL] Adobe Flash Player Has (Another) Critical Zero-Day Vulnerability
Blog / Cyber Exposure Alerts
Subscribe
# Adobe Flash Player Has (Another) Critical Zero-Day Vulnerability
Steve Tilson
June 7, 2018
2 Min Read
The Adobe Flash Player is widely adopted and a choice target for attackers given its history with vulnerabilities and the potential footprint exploits can have. Adobe consistently provides security updates for critical vulnerabilities. However, CVE-2018-5002 is the second zero-day vulnerability in Adobe Flash Player this year (the earlier one being CVE-2018-4877). Today, Adobe released a security patch for this vulnerability, along with other critical updates. This vulnerability was independently discovered by ICEBRG, Qihoo 360 and Tencent and impacts Adobe Flash Player 29.0.0171 and earlier versions. According to Adobe, the vulnerability is a
Tenable
Adobe Flash Player Has (Another) Critical Zero-Day Vulnerability
blogs_tenable·2018-06-07
Adobe Flash Player Has (Another) Critical Zero-Day Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Zscaler
Zscaler found new vulnerabilities in Adobe Flash |02-07-2018
blogs_zscaler
Zscaler found new vulnerabilities in Adobe Flash |02-07-2018
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Zscaler
Zscaler protects against 22 new vulnerabilities for Adobe Fl
blogs_zscaler
Zscaler protects against 22 new vulnerabilities for Adobe Fl
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
CVE-2018-4877 CVE-2018-4878 flash-plugin: use-after-free causing remote code execution (APSB18-03)
bugzilla·2018-02-05·CVSS 9.8
CVE-2018-4877 [CRITICAL] CVE-2018-4877 CVE-2018-4878 flash-plugin: use-after-free causing remote code execution (APSB18-03)
CVE-2018-4877 CVE-2018-4878 flash-plugin: use-after-free causing remote code execution (APSB18-03)
Adobe Security Advisory APSA18-01 for Adobe Flash Player describes an use-after-free flaw that can possibly lead to code exeucution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSA18-01:
Use-after-free Remote Code Execution Critical CVE-2018-4878
Reference:
https://helpx.adobe.com/security/products/flash-player/apsa18-01.html
Discussion:
Fixed Flash Player version is not yet available. Quoting from the Adobe Security Bulletin:
Adobe will address this vulnerability in a release planned for the week of February 5.
---
Updated Flash Player version 28.0.0.161 was released today to correct this issue. The update is documented in the Adobe Security Bul
http://www.securityfocus.com/bid/102930https://access.redhat.com/errata/RHSA-2018:0285https://helpx.adobe.com/security/products/flash-player/apsb18-03.htmlhttp://www.securityfocus.com/bid/102930https://access.redhat.com/errata/RHSA-2018:0285https://helpx.adobe.com/security/products/flash-player/apsb18-03.html
2018-02-06
Published