CVE-2018-15982

HIGH KEV RANSOMWARE

Adobe Flash Player < 31.0.0.153 - Use After Free

Title source: rule

Description

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Exploits (11)

exploitdb WORKING POC
by smgorelik · textlocalwindows
https://www.exploit-db.com/exploits/46051
nomisec WORKING POC 181 stars
by Ridter · client-side
https://github.com/Ridter/CVE-2018-15982_EXP
nomisec WORKING POC 29 stars
by scanfsec · client-side
https://github.com/scanfsec/CVE-2018-15982
nomisec STUB 14 stars
by Ormicron · poc
https://github.com/Ormicron/CVE-2018-15982_PoC
nomisec WORKING POC 12 stars
by jas502n · client-side
https://github.com/jas502n/CVE-2018-15982_EXP_IE
nomisec WORKING POC 11 stars
by kphongagsorn · client-side
https://github.com/kphongagsorn/adobe-flash-cve2018-15982
nomisec WORKING POC 5 stars
by SyFi · poc
https://github.com/SyFi/CVE-2018-15982
gitlab SUSPICIOUS
by 0x1 · poc
https://gitlab.com/0x1/CVE-2018-15982
nomisec WORKING POC
by FlatL1neAPT · poc
https://github.com/FlatL1neAPT/CVE-2018-15982

Scores

CVSS v3 7.8
EPSS 0.9361
EPSS Percentile 99.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-02-15
VulnCheck KEV 2018-11-29
InTheWild.io 2018-11-29
ENISA EUVD EUVD-2018-7838
Ransomware Use Confirmed
CWE
CWE-416
Status published
Products (5)
adobe/flash_player < 31.0.0.153 (4 CPE variants)
adobe/flash_player_installer < 31.0.0.108
redhat/enterprise_linux_desktop 6.0
redhat/enterprise_linux_server 6.0
redhat/enterprise_linux_workstation 6.0
Published Jan 18, 2019
KEV Added Feb 15, 2022
Tracked Since Feb 18, 2026