CVE-2018-4878

ENISA EUVD: EUVD-2018-16663 ↗
Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 4 articles

EPSS Score

Source: FIRST.org · 2026-05-24
93.51%
probability
This CVE has a 93.51% probability of being exploited in the next 30 days.
0% Top 99.8th percentile of all CVEs 100%

CVSS v3.1

Source: NVD
7.8
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

Project Zero
Use-after-free in MediaPlayer DRM Listener

Affected Products

Attack Intelligence

Google Project Zero

Patched
Feb. 6, 2018
Reported by
KrCERT/CC
Root Cause Analysis
???

Exploits & PoC

SyFi/CVE-2018-4878

Flash Exploit Poc

8
B0fH/CVE-2018-4878

Metasploit module for CVE-2018-4878

2
HuanWoWeiLan/SoftwareSystemSecurity-2019

软件系统安全结课作业:[漏洞复现] CVE-2018-4878 Flash 0day

1
KathodeN/CVE-2018-4878

CVE-2018-4878 样本

0
4 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
92%
EPSS 93.51%
CVSS v3.1 7.8
Mentions 4
Last Seen Jun 07, 2018

CNA Information

Analyst Note

This CVE is a confirmed use-after-free vulnerability in Adobe Flash Player with a high CVSS score (7.8) that was actively exploited in the wild in early 2018, demonstrating real-world impact. The vulnerability is documented in Project Zero and has official vendor patch information available, providing strong corroboration of its legitimacy and severity.

Threat Actors 4

Harvester
apt_group Information theft and espionage Unknown
APT3
apt_group Information theft and espionage 🇨🇳 CN
Mirage
apt_group Information theft and espionage 🇨🇳 CN
Naikon
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 03, 2026