CVE-2018-15981 is a critical type confusion vulnerability affecting Adobe Flash Player versions 31.0.0.148 and earlier, impacting products from Adobe, Apple, Google, Linux, Microsoft, and Red Hat. With a CVSS score of 9.8, it presents a severe risk, allowing unauthenticated attackers to achieve arbitrary code execution over a network with low attack complexity. While not currently listed on the KEV catalog or having public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community attention with 12 mentions and two media articles, indicating its historical importance and potential for future exploitation. Despite its inactive status on the Hot List, its high FAUCET Risk Score of 97/100 underscores its significant threat potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 31.0.0.148CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 31.0.0.148CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 31.0.0.148CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 31.0.0.148CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer_11:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.