← Vulnerability feed

Vulnerability record · CVE-2018-15982 · published 18 January 2019

CVE-2018-15982: Adobe Flash Player use-after-free allows code execution

Adobe · Flash Player

Adobe Flash Player 31.0.0.153 and earlier, and 31.0.0.108 and earlier, contain a use-after-free (CWE-416) that can lead to arbitrary code execution. The flaw is remotely reachable through crafted Flash content and has been exploited in the wild, so unpatched or still-installed Flash remains a real risk.

7.8 CVSS 3.1 High CISA KEV since 15 Feb 2022 Known ransomware use EPSS 90% · top 0.2% CWE-416 · Use after free
7.8CVSS 3.1 base score, v2 10.0
90%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
5Affected product versions listed by NVD
10References, 2 tagged exploit
13 Aug 2026Last modified by NVD

Description

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw is remotely triggerable, gives code execution, is in CISA KEV with known ransomware use, and has very high EPSS despite being in an end-of-life product.

What it is

Adobe Flash Player 31.0.0.153 and earlier, and 31.0.0.108 and earlier, contain a use-after-free (CWE-416) that can lead to arbitrary code execution. The flaw is remotely reachable through crafted Flash content and has been exploited in the wild, so unpatched or still-installed Flash remains a real risk.

Impact

An attacker who gets a victim to load malicious Flash content can execute arbitrary code in the context of the affected process, giving full compromise of confidentiality, integrity and availability on the host.

Attack surface

The CVSS vector is local with user interaction required (AV:L/AC:L/PR:N/UI:R), meaning the victim must open or render attacker-supplied content; no authentication is needed. In practice this is reached through a browser or document embedding Flash content.

Exploitation

CVE-2018-15982 is listed in CISA KEV (added 2022-02-15) with known ransomware campaign use, and EPSS is 0.89146 (99.8th percentile); a public Exploit-DB entry (46051) exists. Exploitation is confirmed and active.

What to do

  • Apply the Adobe fix in APSB18-42 (Flash Player 31.0.0.153/31.0.0.108 and later) or the Red Hat errata RHSA-2018:3795 where applicable.
  • Remove or disable Adobe Flash Player entirely; it is end-of-life and CISA's required action is to disconnect the product if still in use.
  • Block Flash content and .swf execution at the browser, email gateway and web proxy layers.
  • Restrict user ability to open untrusted documents and web content that can embed Flash.
  • Inventory endpoints and browsers for any remaining Flash installation and track removal to completion.

Detection

  • Hunt for flash player processes (flashplayerplugin, FlashPlayer.exe) spawning child processes such as cmd.exe, powershell.exe or script hosts.
  • Monitor for .swf files or Flash-embedding documents downloaded from external sources and opened by users.
  • Alert on Office or browser processes loading Flash-related modules and then making outbound network connections.
  • Review proxy and DNS logs for known exploit kit or malicious Flash delivery patterns tied to this CVE.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-15982 to the Known Exploited Vulnerabilities catalog on 15 February 2022 as "Adobe Flash Player Use-After-Free Vulnerability". CISA reports known use in ransomware campaigns. Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 15 August 2022.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-15982 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-5544OpenSLP heap out-of-bounds write in VMware ESXi and Horizon DaaSOpenSLP as shipped in VMware ESXi and Horizon DaaS contains a heap overwrite (out-of-bounds write) flaw. VMware rates it Critical with a maximum CVSS…KEVEPSS 97%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2016-1019Adobe Flash Player memory corruption allows code executionAdobe Flash Player 21.0.0.197 and earlier contains an unspecified memory corruption flaw that can crash the application or allow arbitrary code execu…KEVEPSS 22%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2018-15982), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.