CVE-2018-4877 is a critical use-after-free vulnerability in Adobe Flash Player versions prior to 28.0.0.161, stemming from a dangling pointer in the Primetime SDK's quality of service functionality. This flaw affects various platforms including Adobe, Apple, Google, Linux, Microsoft, and Red Hat. With a CVSS score of 9.8, it allows for unauthenticated, low-complexity remote arbitrary code execution with high impact on confidentiality, integrity, and availability. While no public exploit code is available via Metasploit, Nuclei, or ExploitDB, this vulnerability was reportedly exploited as a zero-day by North Korean hackers, indicating real-world exploitation despite limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 28.0.0.161CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:* | ||
< 28.0.0.161CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.