CVE-2018-4878
ENISA EUVD: EUVD-2018-16663 ↗
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
4 articles
EPSS Score
Source: FIRST.org · 2026-05-24
93.51%
probability
This CVE has a 93.51% probability
of being exploited in the next 30 days.
0%
Top 99.8th percentile of all CVEs
100%
CVSS v3.1
Source: NVD7.8
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
Project ZeroUse-after-free in MediaPlayer DRM Listener
Affected Products
Attack Intelligence
CWE-118
· Incorrect Access of Indexable Resource ('Range Error')
CWE-119
· Buffer Overflow
CWE-416
· Use After Free
CWE-664
· Improper Control of a Resource Through its Lifetime
CWE-666
· Operation on Resource in Wrong Phase of Lifetime
CWE-672
· Operation on a Resource after Expiration or Release
CWE-825
· Expired Pointer Dereference
Google Project Zero
Patched
Feb. 6, 2018
Reported by
KrCERT/CC
Root Cause Analysis
???
Exploits & PoC
SyFi/CVE-2018-4878
Flash Exploit Poc
8
B0fH/CVE-2018-4878
Metasploit module for CVE-2018-4878
2
HuanWoWeiLan/SoftwareSystemSecurity-2019
软件系统安全结课作业:[漏洞复现] CVE-2018-4878 Flash 0day
1
KathodeN/CVE-2018-4878
CVE-2018-4878 样本
0
4 repos — triés par ⭐
Rechercher sur GitHub ↗
New Adobe Flash Zero-Day Spotted in the Wild
BleepingComputer
Feb 01, 2018
Adobe Patches Flash Zero-Day
BleepingComputer
Jun 07, 2018
Security Advisory 2018-005
CERT-EU
Feb 06, 2018
Signal Intelligence
Confidence
92%
EPSS
93.51%
CVSS v3.1
7.8
Mentions
4
Last Seen
Jun 07, 2018
CNA Information
Analyst Note
This CVE is a confirmed use-after-free vulnerability in Adobe Flash Player with a high CVSS score (7.8) that was actively exploited in the wild in early 2018, demonstrating real-world impact. The vulnerability is documented in Project Zero and has official vendor patch information available, providing strong corroboration of its legitimacy and severity.
Threat Actors 4
Triage Info
Decided atMar 03, 2026