CVE 2018-4878 Vulnerability Report

01 Overview

On January 31, 2018, KrCERT/CC warned of a zero-day vulnerability in Adobe Flash Player that was being exploited by malicious actors. The vulnerability, a use-after-free condition in versions 28.0.0.161 and earlier, specifically affected the Primetime SDK’s media player DrmManager. By exploiting a dangling pointer created during listener object handling, attackers could gain unauthorized access to memory and execute malicious code.

CVE Reference
CVE-2018-4878
Ref1. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4878

※ Please refer to the attached PDF for further information.