Back

HIGH KEV Used in ransomware campaigns

flash-plugin: use-after-free causing remote code execution (APSB18-03)

Published Feb 6, 2018 ·Due May 3, 2022

Description

A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Feb 6, 2018
Updated Nov 17, 2025
Reserved Jan 3, 2018
CISA Vulnrichment
Updated Nov 17, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Feb 1, 2018