CVE-2018-4878
KEV RANSOMWAREHIGH 7.8EPSS 89.5%
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 89.53% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03, used in ransomware campaigns
- Published
- 2018-02-06
- Updated
- 2025-11-17
Proof-of-concept exploits (14)
- https://blog.morphisec.com/flash-exploit-cve-2018-4878-spotted-in-the-wild-massive-malspa…
- https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/north-kore…
- B0fH/CVE-2018-48782★ · 2018-10-24
- FlatL1neAPT/Post-exploitation40★ · 2018-03-17
- HuanWoWeiLan/SoftwareSystemSecurity-20191★ · 2019-07-17
- KathodeN/CVE-2018-48780★ · 2018-02-22
- SyFi/CVE-2018-48787★ · 2018-09-03
- Yable/CVE-2018-48780★ · 2018-12-20
- demonsec666/CVE-2018-48780★ · 2018-02-09
- lvyoshino/CVE-2018-48780★ · 2021-04-30
- mdsecactivebreach/CVE-2018-487823★ · 2018-02-09
- nao-sec/ektotal107★ · 2023-01-06
- vysecurity/CVE-2018-487886★ · 2018-02-10
- ydl555/CVE-2018-4878-1★ · 2018-06-12
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/44745
- https://www.exploit-db.com/exploits/44744
- https://www.exploit-db.com/exploits/44412