CVE-2018-12825 is a critical security bypass vulnerability affecting Adobe Flash Player 30.0.0.134 and earlier, impacting various products across Adobe, Apple, Google, Linux, Microsoft, and Red Hat. With a CVSS score of 9.8, it presents a high-severity risk, allowing unauthenticated attackers to bypass security mitigations with low attack complexity, potentially leading to full compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild or readily available exploit code in common repositories like Metasploit or ExploitDB, the vulnerability has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 30.0.0.154CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 30.0.0.154CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 30.0.0.154CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 30.0.0.154CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer_11:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.