CVE-2018-4945 is a Type Confusion vulnerability in Adobe Flash Player versions 29.0.0.171 and earlier, impacting products from Adobe, Apple, Google, Linux, Microsoft, and Red Hat. With a CVSS score of 8.8 (HIGH), it can be exploited remotely with low complexity through user interaction, potentially leading to arbitrary code execution with high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, this vulnerability was reportedly exploited in targeted attacks and received significant community and media attention, despite no public exploit code being available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 29.0.0.171CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 29.0.0.171CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 29.0.0.171CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 29.0.0.171CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer_11:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.