Type Confusion Vulnerability in Adobe Flash Player
CVE-2018-4944
9.8CRITICAL
Key Information:
- Vendor
- Adobe
- Vendor
- CVE Published:
- 19 May 2018
Summary
Adobe Flash Player versions up to 29.0.0.140 are susceptible to a type confusion vulnerability that can be exploited to execute arbitrary code within the current user's session. This could allow an attacker to manipulate user data, install malware, or gain unauthorized access to sensitive information. Users are advised to update their software to mitigate the risks associated with this vulnerability.
Affected Version(s)
Adobe Flash Player 29.0.0.140 and earlier Adobe Flash Player 29.0.0.140 and earlier versions
References
EPSS Score
16% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved