cbcvebase.
CVE-2018-4878
published 2018-02-06

CVE-2018-4878: A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK…

PriorityP192high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
89.53%
99.8th percentile
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.

Affected

4 ranges
VendorProductVersion rangeFixed in
adobeflash_player< 28.0.0.16128.0.0.161
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_workstation

Detection & IOCsextracted from sources · hover to see the quote

hasha795deaa2d1c1f2d9426a8c28791111e0192ffad14d086b51bc61c8e16008b63
  • CVE-2018-4878 is triggered by a crafted SWF file embedded in Office documents distributed via email; detect malicious SWF content inside Office document attachments delivered through email.
  • The exploit is triggered by a crafted SWF file that dereferences a dangling pointer to a listener object in the Primetime SDK; look for SWF files causing access violation exceptions in Flash Player processes.
  • CVE-2018-4878 was deployed by Scarcruft (APT37/North Korean nexus) via Microsoft Word documents distributed through at least one website; monitor for Word documents fetching or embedding Flash content from external URLs.
  • Lazarus Group exploited CVE-2018-4878 for client-side execution; correlate Flash Player exploitation attempts with Lazarus Group TTPs such as spearphishing Word attachments.
  • CVE-2018-4878 was also leveraged by the Spelevo Exploit Kit alongside CVE-2018-15982 to distribute Maze ransomware; monitor exploit kit traffic patterns involving Flash Player vulnerabilities.
  • The Underminer exploit kit uses cookie detection to prevent repeated exploit site visits and user-agent/browser profiling to determine Flash Player version; monitor for these EK fingerprinting behaviors in web proxy logs.
  • Underminer exploit kit uses RSA encryption of traffic prior to exploitation; look for encrypted non-standard traffic patterns preceding Flash exploitation.
  • Tenable Plugin ID 106606 detects Adobe Flash Player <= 28.0.0.137 vulnerable to CVE-2018-4878; use this plugin for asset identification.
  • Tenable Plugin ID 106655 (KB4074595) detects unpatched Adobe Flash Player on Windows; use for patch-status detection.
  • ·Affected versions are Adobe Flash Player 28.0.0.137 and earlier across all platforms (Windows, Macintosh, Linux, Chrome OS); the fixed version is 28.0.0.161. Ensure detections target only these vulnerable version ranges.
  • ·Exploitation requires memory reuse of the freed listener object by another listener object; the mismatch between old and new objects is the condition enabling unintended memory access. Generic use-after-free detections may need tuning for this specific Primetime SDK listener object reuse pattern.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.