Back

HIGH KEV Used in ransomware campaigns

flash-plugin: Arbitrary Code Execution vulnerability (APSB18-42)

Published Jan 18, 2019 ·Due Aug 15, 2022

Description

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (11)

Change history (3)
  1. CISA ADP
    • SSVC automatable changed from yes to no
  2. CISA ADP
    • SSVC automatable changed from no to yes
  3. CISA ADP
    • SSVC automatable changed from yes to no
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Jan 18, 2019
Updated Oct 1, 2026
Reserved Aug 28, 2018
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Analyzed
Modified Aug 13, 2026
Red Hat
Severity Critical
Public date Dec 5, 2018