ZeroHour

CVE-2018-5002

KEVmass

Stack Buffer Overflow RCE in Adobe Flash Player

CISA: Adobe Flash Player Stack-based Buffer Overflow Vulnerability

CVSS 3.1
7.8 high
EPSS
25%p98
Published
()
KEV added
AI analysis

CVE-2018-5002 is a stack-based buffer overflow (out-of-bounds write) in Adobe Flash Player that can lead to remote code execution. It is triggered when the affected Flash Player processes malicious Flash content, typically delivered remotely through a browser or another application that renders SWF content. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Flash Player. Anyone still running affected versions of Adobe Flash Player is affected, though the product is now end-of-life, and CISA's required action is to disconnect or remove it if still in use. The flaw is being exploited in the wild per its inclusion in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), with a 25.4% EPSS probability of exploitation within 30 days (98th percentile); no public PoC is known.

What to do: Because Flash Player is end-of-life, the recommended action is to fully uninstall Adobe Flash Player from all systems, prioritizing internet-facing and server workstations, and block or disable Flash content in browsers. Where Flash cannot yet be removed, ensure the latest available Flash release with the 2018 vendor fix for this issue is installed and restrict rendering of untrusted SWF content. Hunt for signs of exploitation per the KEV entry, and treat any remaining Flash-enabled endpoint as a legacy-asset risk.

Affected
Adobe Flash PlayerAll versions released prior to the vendor's 2018 security update addressing this flaw; the product is now end-of-life (no patched release line is maintained)
Estimated exposure
mass≈ tens of millions of legacy installations worldwide (Flash Player historically shipped on nearly every Windows PC and in major browsers) — Estimated from Flash Player's historic ubiquity as a pre-installed/bundled component on Windows systems and browsers, offset by its end-of-life status, which means exposure today is concentrated in legacy enterprise, industrial, and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
adoberedhat
Products
flash player desktop runtime, flash player, enterprise linux desktop, enterprise linux server, enterprise linux workstation
Weakness
CWE-787, CWE-121
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news