Type Confusion Vulnerability in Adobe Flash Player
CVE-2018-4920

8.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
19 May 2018

Summary

Adobe Flash Player versions 28.0.0.161 and earlier contain a type confusion vulnerability that can be exploited by attackers. This vulnerability may allow for arbitrary code execution within the context of an affected user's session. By leveraging this weakness, malicious entities could gain unauthorized access to a system, posing significant security risks. Users are advised to update to the latest version of the software to mitigate potential threats associated with this vulnerability.

Affected Version(s)

Adobe Flash Player 28.0.0.161 and earlier Adobe Flash Player 28.0.0.161 and earlier versions

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.