CVE-2018-4878

HIGH KEV RANSOMWARE

Adobe Flash Player < 28.0.0.161 - Use After Free

Title source: rule

Description

A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.

Exploits (18)

exploitdb WORKING POC
by SyFi · pythonremotemultiple
https://www.exploit-db.com/exploits/44412
exploitdb WORKING POC
by smgorelik · textlocalwindows
https://www.exploit-db.com/exploits/44744
exploitdb WORKING POC
by smgorelik · textlocalwindows
https://www.exploit-db.com/exploits/44745
github WRITEUP 3,480 stars
by qazbnm456 · poc
https://github.com/qazbnm456/awesome-cve-poc/tree/master/CVE-2018-4878.md
nomisec WORKING POC 87 stars
by vysecurity · client-side
https://github.com/vysecurity/CVE-2018-4878
nomisec WORKING POC 23 stars
by mdsecactivebreach · client-side
https://github.com/mdsecactivebreach/CVE-2018-4878
github WRITEUP 14 stars
by xbl3 · poc
https://github.com/xbl3/awesome-cve-poc_qazbnm456/tree/master/CVE-2018-4878.md
nomisec WORKING POC 8 stars
by SyFi · client-side
https://github.com/SyFi/CVE-2018-4878
nomisec WORKING POC 2 stars
by B0fH · client-side
https://github.com/B0fH/CVE-2018-4878
nomisec WORKING POC 1 stars
by HuanWoWeiLan · client-side
https://github.com/HuanWoWeiLan/SoftwareSystemSecurity-2019
nomisec SUSPICIOUS 1 stars
by ydl555 · poc
https://github.com/ydl555/CVE-2018-4878-
gitlab WORKING POC
by 0x1 · client-side
https://gitlab.com/0x1/CVE-2018-4878
nomisec WORKING POC
by lvyoshino · client-side
https://github.com/lvyoshino/CVE-2018-4878
nomisec WORKING POC
by Yable · poc
https://github.com/Yable/CVE-2018-4878
nomisec WORKING POC
by KathodeN · client-side
https://github.com/KathodeN/CVE-2018-4878
nomisec WORKING POC
by demonsec666 · poc
https://github.com/demonsec666/CVE-2018-4878

References (16)

Scores

CVSS v3 7.8
EPSS 0.9351
EPSS Percentile 99.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2018-02-03
InTheWild.io 2018-02-06
ENISA EUVD EUVD-2018-16663
Ransomware Use Confirmed
CWE
CWE-416
Status published
Products (4)
adobe/flash_player < 28.0.0.161 (4 CPE variants)
redhat/enterprise_linux_desktop 6.0
redhat/enterprise_linux_server 6.0
redhat/enterprise_linux_workstation 6.0
Published Feb 06, 2018
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026