ZeroHour

CVE-2018-15982

KEV ransomware PoC mass

Use-After-Free in Adobe Flash Player Allows Arbitrary Code Execution

CISA: Adobe Flash Player Use-After-Free Vulnerability

CVSS 3.1
7.8 high
EPSS
89%p100
Published
()
KEV added
AI analysis

CVE-2018-15982 is a use-after-free flaw (CWE-416) in Adobe Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier, in which Flash frees memory that is subsequently reused, corrupting process memory. It is triggered when Flash processes crafted Flash content, most notably embedded in Microsoft Office documents, requiring a user to open or view the malicious content (CVSS attack vector is local with user interaction required). Successful exploitation gives the attacker arbitrary code execution with the privileges of the user viewing the content. Affected users include anyone running the listed Flash Player versions, including the Flash Player Installer and the Adobe-supplied Flash plugin shipped with Red Hat Enterprise Linux Desktop, Server and Workstation. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-15) with known ransomware use, a public exploit is available on Exploit-DB, and EPSS assigns a top-percentile 89.1% probability of exploitation within 30 days.

What to do: Flash Player is end-of-life: per CISA's required action, remove or disconnect Flash wherever it is still in use; if Flash must remain, update beyond the affected 31.0.0.153/31.0.0.108 builds and update the flash-plugin package on Red Hat Enterprise Linux. Mitigate the known delivery vector by blocking or disabling embedded Flash (SWF) content in Microsoft Office documents and mail clients, and hunt for suspicious documents with embedded Flash given the known in-the-wild and ransomware use.

Affected
Adobe Flash Player31.0.0.153 and earlier, and 31.0.0.108 and earlier
Adobe Flash Player InstallerSame affected ranges as Flash Player (31.0.0.153 and earlier / 31.0.0.108 and earlier)
Red Hat Enterprise Linux Desktop (Adobe-supplied flash-plugin)
Red Hat Enterprise Linux Server (Adobe-supplied flash-plugin)
Red Hat Enterprise Linux Workstation (Adobe-supplied flash-plugin)
Estimated exposure
mass≈100M+ endpoints historically (Flash was preinstalled/bundled across most Windows desktops and shipped with Chrome and RHEL in 2018); only residual legacy… — Estimate based on Flash Player's near-ubiquitous distribution at disclosure — bundled into major browsers, preinstalled with Windows, and packaged by Red Hat — giving an installed base in the hundreds of millions, now reduced to isolated…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Known
Vendors
adoberedhat
Products
flash player, enterprise linux desktop, enterprise linux server, enterprise linux workstation, flash player installer
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Threat Brief: Maze Ransomware

Unit 42 issued a threat brief on Maze ransomware, noting an uptick across industries and exploitation of Pulse VPN and IE flaws for initial access.

Palo Alto Networks detected an uptick in Maze ransomware samples across finance, healthcare, government, and other sectors. Maze, a variant of ChaCha ransomware first seen in May 2019, is distributed via weaponized Word/Excel attachments and the Spelevo exploit kit leveraging CVE-2018-15982 and CVE-2018-4878, and has used CVE-2019-11510 (Pulse VPN) and CVE-2018-8174 (Internet Explorer). Operators establish a foothold, escalate privileges, move laterally, and exfiltrate files before encryption for extortion leverage.

Palo Alto Unit 42 · 29d agoRansomware in the wildCVE-2018-15982CVE-2018-4878CVE-2019-11510+1 CVEs