VDB
CVE-2018-4878
CVE-2018-4878
PUBLISHED
KEV
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
EPSS 93.51% · 99.8th percentile
Risk Scores
EPSS Score
93.51%
99.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | flashplugin-nonfree | 0, 11.2.202.540ubuntu2, 11.2.202.548ubuntu1 |
| Ubuntu:14.04:LTS | flashplugin-nonfree | 11.2.202.626ubuntu0.14.04.1, 11.2.202.632ubuntu0.14.04.1, 11.2.202.635ubuntu0.14.04.1 |
Exploit Intelligence
- Yable/CVE-2018-4878 (github-poc-repo)
- Yable/CVE-2018-4878 (github-poc-repo)
- Yable/CVE-2018-4878 (github-poc-repo)
- Yable/CVE-2018-4878 (github-poc-repo)
- Yable/CVE-2018-4878 (github-poc-repo)
- Yable/CVE-2018-4878 (github-poc-repo)
- Yable/CVE-2018-4878 (github-poc-repo)
- Yable/CVE-2018-4878 (github-poc-repo)
- 软件系统安全结课作业:[漏洞复现] CVE-2018-4878 Flash 0day (github-poc-repo)
- 软件系统安全结课作业:[漏洞复现] CVE-2018-4878 Flash 0day (github-poc-repo)
…and 191 more exploits
Timeline
- Jan 19, 1970 VulnCheck XDB Entry
- Jul 5, 2015 VulnCheck KEV Exploitation
- Jul 21, 2015 VulnCheck KEV Exploitation
- Aug 10, 2015 VulnCheck KEV Exploitation
- Feb 3, 2016 VulnCheck KEV Exploitation
- Jan 9, 2017 VulnCheck KEV Exploitation
- Feb 2, 2018 CVE Published
- Feb 2, 2018 PoC Published
- Feb 4, 2018 VulnCheck KEV Exploitation
- Feb 6, 2018 PoC Published
- Feb 24, 2018 PoC Published
- Apr 4, 2018 PoC Published
References
- https://ubuntu.com/security/CVE-2018-4878 third-party-advisory
- https://helpx.adobe.com/security/products/flash-player/apsb18-03.html third-party-advisory
- https://threatpost.com/adobe-flash-player-zero-day-spotted-in-the-wild/129742/ third-party-advisory
- https://www.fireeye.com/blog/threat-research/2018/02/attacks-leveraging-adobe-zero-day.html third-party-advisory
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/north-korean-hackers-allegedly-exploit-adobe-flash-player-vulnerability-cve-2018-4878-against-south-korean-targets third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-4878 third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog third-party-advisory
- Vulnérabilité dans Adobe Flash Player advisory