CVE-2018-15983

HIGH

Flash Player < 31.0.0.153 - Privilege Escalation via DLL Hijacking

Title source: llm
STIX 2.1

Description

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106108

Scores

CVSS v3 7.8
EPSS 0.0328
EPSS Percentile 86.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-426
Status published
Products (1)
adobe/flash_player < 31.0.0.153 (4 CPE variants)
Published Jan 18, 2019
Tracked Since Feb 18, 2026