CVE-2018-4878
HIGH KEV RANSOMWAREAdobe Flash Player < 28.0.0.161 - Use-After-Free in Primetime SDK Media Player Listener Handling
Title source: llmExploitation Summary
CVE-2018-4878 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021, with confirmed use in ransomware campaigns. EIP tracks 16 public exploits from researchers including SyFi, smgorelik, qazbnm456.
AI-analyzed exploit summary This exploit leverages CVE-2018-4878, a use-after-free vulnerability in Adobe Flash Player, to achieve remote code execution (RCE) via a crafted SWF file. The payload includes shellcode generated by Msfvenom to execute calc.exe, demonstrating the vulnerability's exploitability.
Description
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
Exploits (16)
This exploit leverages CVE-2018-4878, a use-after-free vulnerability in Adobe Flash Player, to achieve remote code execution (RCE) via a crafted SWF file. The payload includes shellcode generated by Msfvenom to execute calc.exe, demonstrating the vulnerability's exploitability.
This exploit targets CVE-2018-4878, a vulnerability in Adobe Flash Player. It leverages a crafted Excel file to trigger a use-after-free condition, leading to remote code execution (RCE) by popping a calculator as a proof-of-concept.
This exploit targets CVE-2018-4878, a use-after-free vulnerability in Adobe Flash Player. The provided SWF file triggers the vulnerability to achieve remote code execution, demonstrated by popping up a calculator.
This repository provides a curated list of references and external resources related to CVE-2018-4878, a critical Adobe Flash Player vulnerability involving a use-after-free (UAF) bug. It includes links to technical analyses, malware samples, and advisory reports but does not contain direct exploit code.
This repository contains an Aggressor script for Cobalt Strike that exploits CVE-2018-4878, a vulnerability in Adobe Flash Player before February 2018. The exploit is designed to be hosted and delivered via Internet Explorer, resulting in a reverse shell within the IE sandbox.
This repository contains a proof-of-concept exploit for CVE-2018-4878, a critical Adobe Flash Player vulnerability. The exploit leverages a use-after-free bug to achieve remote code execution (RCE) via a malicious SWF file.
This repository provides a curated list of references and external resources related to CVE-2018-4878, a Flash Player UAF vulnerability. It includes links to PoC samples, technical analyses, and advisory reports but does not contain direct exploit code.
This is a Python-based proof-of-concept exploit for CVE-2018-4878, a use-after-free vulnerability in Adobe Flash Player. It delivers a shellcode payload (calc.exe) via a malicious SWF file served over HTTP, targeting Flash Player versions prior to the fix.
This is a Metasploit module exploiting CVE-2018-4878, a use-after-free vulnerability in Adobe Flash Player. It leverages a DRM manager object reference issue to achieve remote code execution on vulnerable systems.
This is a Python script that generates a malicious SWF file exploiting CVE-2018-4878, a critical Adobe Flash Player remote code execution vulnerability. The exploit embeds shellcode to spawn a reverse shell and uses a crafted RDF structure to trigger the vulnerability.
The repository contains a README.md with minimal content in Chinese, mentioning server cluster CMS identification, backup finding, and injection, but lacks actual exploit code or technical details for CVE-2018-4878.
This repository contains a functional exploit for CVE-2018-4878, a use-after-free vulnerability in Adobe Flash Player. The exploit uses a crafted SWF file delivered via an HTTP server to achieve remote code execution (RCE) by executing a calc.exe shellcode.
This is a Python-based exploit for CVE-2018-4878, a critical Adobe Flash Player remote code execution vulnerability. It leverages a crafted SWF file with embedded shellcode to achieve arbitrary code execution on vulnerable systems.
This is a Python-based exploit for CVE-2018-4878, a critical Adobe Flash Player remote code execution vulnerability. It includes shellcode and constructs a malicious SWF file to trigger the vulnerability.
This repository contains a Python script that generates an exploit for CVE-2018-4878, a vulnerability in Adobe Flash Player. The script embeds a Metasploit-generated shellcode (default payload is a Windows calculator) into a malicious SWF file.
This is an Aggressor Script for Cobalt Strike that weaponizes CVE-2018-4878, a Flash Player vulnerability, to deliver a payload via an Internet Explorer drive-by attack. The exploit targets outdated versions of Adobe Flash Player before February 2017.
References (16)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H