cbcvebase.
CVE-2018-4935
published 2018-05-19

CVE-2018-4935: Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code…

PriorityP266high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
26.16%
97.8th percentile
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Affected

2 ranges
VendorProductVersion rangeFixed in
adobeflash_player<= 29.0.0.113
adobeflash_player_desktop_runtime<= 29.0.0.113

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/44527.zip
  • Trigger is a crafted SWF file; inspect SWF files for anomalous slab/solid-slab graphics element structures that may exploit out-of-range pointer arithmetic in the graphics rendering path.
  • Monitor Flash Player processes (standalone player and Microsoft Edge) for heap or stack corruption crashes during SWF rendering, particularly in slab rendering routines.
  • Flag delivery of SWF files that trigger the slab/solid-slab graphics rendering code path; the vulnerability is exercised during graphics rendering of solid slab elements, distinct from blur or audio processing paths.
  • ·Affected versions are Adobe Flash Player 29.0.0.113 and earlier across all platforms (Windows, Macintosh, Linux, Chrome OS); exploitation requires the victim to open a specially crafted SWF file.
  • ·The PoC crash reliability varies by platform; most reliable in standalone Flash Player and Microsoft Edge, less so in other environments — detection based on crash telemetry may have lower fidelity on other platforms.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.