CVE-2018-4878 is a critical use-after-free vulnerability in Adobe Flash Player versions prior to 28.0.0.161, stemming from a dangling pointer in the Primetime SDK. This flaw affects a wide range of products across Adobe, Apple, Google, Linux, Microsoft, and Red Hat. With a CVSS score of 7.8 (High) and an EPSS score indicating high exploitability, successful exploitation can lead to arbitrary code execution. This vulnerability has been actively exploited in the wild, including in known ransomware campaigns, and multiple public exploits are available on ExploitDB. The high volume of community discussion and media coverage underscores its significant impact and widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 28.0.0.161CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:* | ||
< 28.0.0.161CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.