CVE-2018-15982

ENISA EUVD: EUVD-2018-7838 ↗
Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 5, 2026 2 articles Published: 2019-01-18

EPSS Score

Source: FIRST.org · 2026-05-23
93.61%
probability
This CVE has a 93.61% probability of being exploited in the next 30 days.
0% Top 99.8th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
7.8
HIGH
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2 (legacy)

10.0
HIGH
Access Vector
Network
Access Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
AV:N/AC:L/Au:N/C:C/I:C/A:C

Description

VulnerabilityLookup (CNA)
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Affected Products

n/a
n/a

Attack Intelligence

Google Project Zero

Discovered
Nov. 29, 2018
Patched
Dec. 5, 2018
Reported by
Chenming Xu and Ed Miles of Gigamon ATR, Yang Kang (@dnpushme) and Jinquan (@jq0904) of Qihoo 360 Core Security (@360CoreSec), He Zhiqiu, Qu Yifan, Bai Haowen, Zeng Haitao and Gu Liang of 360 Threat Intelligence of 360 Enterprise Security Group, b2ahex
Root Cause Analysis
???

Exploits & PoC

Ridter/CVE-2018-15982_EXP

exp of CVE-2018-15982

180 2019-01-04
scanfsec/CVE-2018-15982

Aggressor Script to launch IE driveby for CVE-2018-15982.

29 2019-12-07
13 2019-11-06
jas502n/CVE-2018-15982_EXP_IE

CVE-2018-15982_EXP_IE

12 2018-12-12
kphongagsorn/adobe-flash-cve2018-15982

Script and metasploit module for CVE-2018-15982

11 2020-08-12
SyFi/CVE-2018-15982

Flash 2018-15982 UAF

5 2018-12-20
FlatL1neAPT/CVE-2018-15982

Flash sources for CVE-2018-15982 used by NK

0 2018-12-05
8 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
95%
EPSS 93.61%
CVSS v3.1 7.8
Mentions 2
Last Seen Dec 11, 2018

CNA Information

CNA Assigner
adobe

Analyst Note

Auto-imported from Google Project Zero — confirmed zero-day by definition.

Threat Actors 2

Kinsing
apt_group 🇷🇺 RU
TeamTNT
apt_group 🇩🇪 DE

Triage Info

Decided atMar 05, 2026
Published DateJan 18, 2019