Vulnerability record · CVE-2018-15982 · published 18 January 2019
CVE-2018-15982: Adobe Flash Player use-after-free allows code execution
Adobe · Flash Player
Adobe Flash Player 31.0.0.153 and earlier, and 31.0.0.108 and earlier, contain a use-after-free (CWE-416) that can lead to arbitrary code execution. The flaw is remotely reachable through crafted Flash content and has been exploited in the wild, so unpatched or still-installed Flash remains a real risk.
Description
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw is remotely triggerable, gives code execution, is in CISA KEV with known ransomware use, and has very high EPSS despite being in an end-of-life product.
What it is
Adobe Flash Player 31.0.0.153 and earlier, and 31.0.0.108 and earlier, contain a use-after-free (CWE-416) that can lead to arbitrary code execution. The flaw is remotely reachable through crafted Flash content and has been exploited in the wild, so unpatched or still-installed Flash remains a real risk.
Impact
An attacker who gets a victim to load malicious Flash content can execute arbitrary code in the context of the affected process, giving full compromise of confidentiality, integrity and availability on the host.
Attack surface
The CVSS vector is local with user interaction required (AV:L/AC:L/PR:N/UI:R), meaning the victim must open or render attacker-supplied content; no authentication is needed. In practice this is reached through a browser or document embedding Flash content.
Exploitation
CVE-2018-15982 is listed in CISA KEV (added 2022-02-15) with known ransomware campaign use, and EPSS is 0.89146 (99.8th percentile); a public Exploit-DB entry (46051) exists. Exploitation is confirmed and active.
What to do
- Apply the Adobe fix in APSB18-42 (Flash Player 31.0.0.153/31.0.0.108 and later) or the Red Hat errata RHSA-2018:3795 where applicable.
- Remove or disable Adobe Flash Player entirely; it is end-of-life and CISA's required action is to disconnect the product if still in use.
- Block Flash content and .swf execution at the browser, email gateway and web proxy layers.
- Restrict user ability to open untrusted documents and web content that can embed Flash.
- Inventory endpoints and browsers for any remaining Flash installation and track removal to completion.
Detection
- Hunt for flash player processes (flashplayerplugin, FlashPlayer.exe) spawning child processes such as cmd.exe, powershell.exe or script hosts.
- Monitor for .swf files or Flash-embedding documents downloaded from external sources and opened by users.
- Alert on Office or browser processes loading Flash-related modules and then making outbound network connections.
- Review proxy and DNS logs for known exploit kit or malicious Flash delivery patterns tied to this CVE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-15982 to the Known Exploited Vulnerabilities catalog on 15 February 2022 as "Adobe Flash Player Use-After-Free Vulnerability". CISA reports known use in ransomware campaigns. Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 15 August 2022.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/106116 | Broken LinkThird Party AdvisoryVDB Entry |
| https://access.redhat.com/errata/RHSA-2018:3795 | Third Party Advisory |
| https://helpx.adobe.com/security/products/flash-player/apsb18-42.html | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/46051/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/106116 | Broken LinkThird Party AdvisoryVDB Entry |
| https://access.redhat.com/errata/RHSA-2018:3795 | Third Party Advisory |
| https://helpx.adobe.com/security/products/flash-player/apsb18-42.html | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/46051/ | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/cisagov/vulnrichment/issues/195 | Issue Tracking |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-15982 | Third Party AdvisoryUS Government Resource |
Track CVE-2018-15982 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-15982), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.