Type Confusion Vulnerability in Adobe Flash Player
CVE-2018-4920
8.8HIGH
Key Information:
- Vendor
- Adobe
- Vendor
- CVE Published:
- 19 May 2018
Summary
Adobe Flash Player versions 28.0.0.161 and earlier contain a type confusion vulnerability that can be exploited by attackers. This vulnerability may allow for arbitrary code execution within the context of an affected user's session. By leveraging this weakness, malicious entities could gain unauthorized access to a system, posing significant security risks. Users are advised to update to the latest version of the software to mitigate potential threats associated with this vulnerability.
Affected Version(s)
Adobe Flash Player 28.0.0.161 and earlier Adobe Flash Player 28.0.0.161 and earlier versions
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved