← Back to browse · API

CVE-2018-4878

Severity
HIGH
CVSS
7.8
EPSS
0.89532
Risk score
56.34
CISA KEV
Yes
PoC
No
Published
2018-02-06
Modified
2025-11-17
First seen
2026-08-07
Aliases
EUVD-2018-16663, GHSA-2RF4-MPG3-PHJW
Products
Adobe:Flash Player, n/a:Adobe Flash Player before 28.0.0.161 Adobe Flash Player before 28.0.0.161
Sources
cisa.gov CVE-2018-4878
euvd EUVD-2018-16663

Description

A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.

References