Vulnerability CVE-2018-4920: Information

Description

Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: May 19, 2018
Modified: Nov. 18, 2022
Error type identifier: CWE-843

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
adobe-flash-player-ppapip929-alt1.S132-alt118ALT-PU-2018-1663-1205651Fixed
adobe-flash-player-ppapip829-alt1.M80P.132-alt118ALT-PU-2018-1675-1205652Fixed
adobe-flash-player-ppapic9f229-alt1.S132-alt115ALT-PU-2018-1663-1205651Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://helpx.adobe.com/security/products/flash-player/apsb18-05.html
  • Patch
  • Vendor Advisory
RHSA-2018:0520
  • Third Party Advisory
1040509
  • Broken Link
  • Third Party Advisory
  • VDB Entry
103383
  • Broken Link
  • Third Party Advisory
  • VDB Entry
    1. Configuration 1

      cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:*

      Running on/with:
      cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:google:chrome_os:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:*

      cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*