#VU13226 Type confusion in Adobe Flash Player - CVE-2018-4945
Published: June 7, 2018
Vulnerability identifier: #VU13226
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2018-4945
CWE-ID: CWE-843
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Adobe Flash Player
Adobe Flash Player
Software vendor:
Adobe
Adobe
Description
The vulnerability allows a remote attacker to compromise target system.
The vulnerability exists due to a type confusion error when processing .swf files. A remote attacker can create a specially crafted .swf file, trick the victim into opening it and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow the attacker to compromise vulnerable system.
Remediation
Update to version 30.0.0.113.