Skip to main content

CVE detail

CVE-2018-15982

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS 7.8 · HighBuzz score 72.5KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 72.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
35 evidence mentions in the snapshot
Diversity score
17.5
7 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
35 source links · newest first
  • The United States Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday announced that it has expanded its Known Exploited Vulnerabilities Catalog with nine more security flaws, including two recently addressed zero-days.

    newswww.securityweek.comFeb 16, 2022, 12:52 PM
  • The U.S. CISA added to the Known Exploited Vulnerabilities Catalog another 9 security flaws actively exploited in the wild. US Cybersecurity and Infrastructure Security Agency (CISA) added nine new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including two recently patched zero-day issues affecting Adobe Commerce/Magento Open Source and Google Chrome. CISA orders all Federal Civilian Executive […]

    newssecurityaffairs.comFeb 16, 2022, 10:04 AM
  • What is Egregor?Egregor ransomware is a relatively new ransomware (first spotted in September 2020) that seems intent on making its way…

    newswww.malwarebytes.comDec 14, 2020, 5:00 PM
  • A cybercrime group named Malàsmoke has been targeting porn sites over the past months with malicious ads redirecting users to exploit kits. A cybercrime group named Malàsmoke has been targeting porn sites over the past months, it is placing malicious ads on adult-themed websites to redirect users to exploit kits and deliver malware. According to […]

    newssecurityaffairs.comSep 12, 2020, 12:05 PM
  • Malvertising campaigns come back in full swingMalwarebytes Labs

    Malvertising campaigns leading to exploit kits are nowhere near as common these days. Indeed, a number of threat actors have moved…

    newswww.malwarebytes.comSep 8, 2020, 5:00 PM
  • We've detected an uptick in Maze ransomware samples across multiple industries and created a general threat assessment post on the group behind it.

    vendorunit42.paloaltonetworks.comMay 8, 2020, 1:00 PM
  • The number of identified zero-day vulnerabilities being exploited has increased in 2019, revealing a broadened access to these security flaws, according to security firm FireEye.

    newswww.securityweek.comApr 7, 2020, 8:15 PM
  • Which ten software vulnerabilities should you patch as soon as possible (if you haven’t already)? Table of top exploited CVEs between 2016 and 2019 (repeats are noted by color) Recorded Future researchers have analyzed code repositories, underground forum postings, dark web sites, closed source reports and data sets comprising of submissions to popular malware repositories to compile a list of the ten most exploited vulnerabilities by cybercriminals in 2019. The list The list is comprised … More →

    newswww.helpnetsecurity.comFeb 6, 2020, 6:30 AM
  • Exploit kits: fall 2019 reviewMalwarebytes Labs

    Despite a slim browser market share, Internet Explorer is still being exploited in fall 2019 in a number of drive-by download…

    newswww.malwarebytes.comNov 18, 2019, 5:00 PM
  • A recently discovered exploit kit dubbed Capesand is being involved in live attacks despite the fact that it’s still under development. In October 2019, researchers at TrendMicro discovered a new exploit kit dubbed Capesand that is being involved in live attacks. The tool was discovered while analyzing a malvertising campaign employing the RIG EK to […]

    newssecurityaffairs.comNov 8, 2019, 11:01 AM
  • A newly discovered exploit kit (EK) is being employed in live attacks despite the fact that it’s still in an unfinished state, Trend Micro’s security researchers reveal.

    newswww.securityweek.comNov 8, 2019, 7:29 AM
  • Security experts discovered a new exploit kit, dubbed Lord Exploit Kit, that is currently targeting vulnerable versions of Adobe Flash Player. Security experts at Malwarebytes have recently discovered a new exploit kit, dubbed Lord Exploit Kit, that is targeting vulnerable versions of Adobe Flash Player The Lord Exploit Kit was first detected by Adrian Luca, […]

    newssecurityaffairs.comAug 7, 2019, 6:35 AM
  • New ‘Lord’ Exploit Kit EmergesSecurityWeek

    A newly identified exploit kit is targeting vulnerable versions of Adobe’s Flash Player, Malwarebytes security researchers say.

    newswww.securityweek.comAug 6, 2019, 6:10 PM
  • Say hello to Lord Exploit KitMalwarebytes Labs

    The initial payload was njRAT, however the threat actors switched it the next day for the ERIS ransomware, as spotted by…

    newswww.malwarebytes.comAug 1, 2019, 5:00 PM
  • Cobalt Group Returns To KazakhstanCheck Point Research

    Introduction Cobalt Group is a financially motivated cyber-crime gang that has been active since at least 2016. The group is mainly interested in carrying out attacks against banks, in an attempt to access the banks’ internal networks and potentially take over sensitive components, such as ATM-controlling servers or card-processing systems. Although the Europol arrested Cobalt […]

    vendorresearch.checkpoint.comJul 31, 2019, 2:14 PM
  • Exploit kits: summer 2019 reviewMalwarebytes Labs

    In the months since our last spring review, there has been some interesting activity from several exploit kits. While the playing…

    newswww.malwarebytes.comJul 29, 2019, 5:00 PM
  • Researchers at Cisco Talos group have discovered a new exploit kit dubbed Spelevo that spreads via a compromised business-to-business website. Malware researchers at Cisco Talos have discovered a new exploit kit dubbed Spelevo that spreads via a compromised business-to-business website. The popularity of EK rapidly decreased with the demise of the Angler Exploit Kit, but the discovery […]

    newssecurityaffairs.comJun 29, 2019, 5:08 AM
  • A newly discovered exploit kit is being disseminated via a compromised business-to-business website, Cisco Talos security researchers report.

    newswww.securityweek.comJun 28, 2019, 2:07 PM
  • Exploit kits: spring 2019 reviewMalwarebytes Labs

    Exploit kit activity remains fairly unchanged since our last winter review in terms of active distribution campaigns. But this spring edition…

    newswww.malwarebytes.comMay 13, 2019, 5:00 PM
  • Eight of the top ten most exploited vulnerabilities in 2018 affected Microsoft products. Only one — but the second most exploited — was an Adobe vulnerability. The last one, ranking at the ninth most exploited vulnerability of 2018, was an Android vulnerability.

    newswww.securityweek.comMar 19, 2019, 4:26 PM
  • Exploit kits: winter 2019 reviewMalwarebytes Labs

    Active malvertising campaigns in December and the new year have kept exploit kit activity from hibernating in winter 2019. We mostly…

    newswww.malwarebytes.comFeb 11, 2019, 5:00 PM
  • A recent Windows Defender Advanced Threat Protection (ATP) alert described an Adobe Flash zero-day vulnerability (CVE-2018-15982) that was used in a spear-phishing attack against a medical institution in Russia. Adobe released a patch on December 5, 2018. This vulnerability and attack sequence highlighted a number of mitigations that you can use to block such attacks. […]

    newswww.csoonline.comJan 30, 2019, 11:00 AM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Let me inform you that my new book, “Digging in the Deep Web” is online with a special deal 20% discount Kindle Edition Paper Copy Once again thank you! TA505 Group adds new ServHelper Backdoor and FlawedGrace […]

    newssecurityaffairs.comJan 20, 2019, 1:32 PM
  • Experts at Malwarebytes have reported that the code for the recently discovered Flash zero-day flaw was added to the Fallout Exploit kit. Experts at Malwarebytes observed a new version of the Fallout Exploit kit that include the code to exploit a recently discovered Flash zero-day vulnerability. The Fallout Exploit kit was discovered at the end […]

    newssecurityaffairs.comJan 18, 2019, 11:22 PM
  • An updated version of the Fallout exploit kit recently emerged with an exploit for a recent Flash zero-day included in its arsenal, Malwarebytes Labs security researchers warn.

    newswww.securityweek.comJan 18, 2019, 8:30 PM
  • Improved Fallout EK comes back after short hiatusMalwarebytes Labs

    [Edit 2019-01-24] Fallout EK introduces a new dropper to facilitate the final payload retrieval. This update replaces the plain MZ we…

    newswww.malwarebytes.comJan 16, 2019, 5:00 PM
  • One of the most interesting exploit kits we track is also a bit of an elusive one, and as such does…

    newswww.malwarebytes.comDec 20, 2018, 5:00 PM
  • It’s Patch Tuesday again and, as per usual, both Microsoft and Adobe have pushed out patches for widely-used software packages. The Microsoft patches Microsoft’s December 2018 Patch Tuesday release is pretty lightweight: the company has plugged 38 CVE-numbered security holes, nine of which are considered to be Critical. Among the most notable bugs in this batch are CVE-2018-8611, an elevation of privilege vulnerability that arises when the Windows kernel fails to properly handle objects in … More →

    newswww.helpnetsecurity.comDec 12, 2018, 12:43 PM
  • Here’s an overview of some of last week’s most interesting news and articles: Old and new OpenSSH backdoors threaten Linux servers OpenSSH, a suite of networking software that allows secure communications over an unsecured network, is the most common tool for system administrators to manage rented Linux servers. And given that over one-third of public-facing internet servers run Linux, it shouldn’t come as a surprise that threat actors would exploit OpenSSH’s popularity to gain control … More →

    newswww.helpnetsecurity.comDec 9, 2018, 6:48 PM
  • Grab your shovels, dust off the snow blower, and bundle up. The way patches are accumulating this month is making me think of winter in Minnesota. I’m talking about the kind where the snow flurries start and stop so many times over the course of a few weeks, you suddenly realize there is a lot of snow out there! So the question is, do you shovel in small amounts when there are breaks in the … More →

    newswww.helpnetsecurity.comDec 7, 2018, 6:30 AM
  • Ukraine is accusing Russian intelligence services of carrying out cyberattacks against one of its government organizations. Ukraine’s security service SBU announced to have blocked a cyber attack launched by Russian intelligence aimed at breaching information and telecommunications systems used by the country’s judiciary. Attackers launched a spear phishing attack using messages purporting to deliver accounting documents. […]

    newssecurityaffairs.comDec 6, 2018, 12:14 PM
  • Adobe patches newly exploited Flash zero-dayHelp Net Security

    Adobe has released an out-of-band security update for Flash Player that fixes two vulnerabilities, one of which is a zero-day (CVE-2018-15982) that has been spotted being exploited in the wild. About the vulnerability (CVE-2018-15982) CVE-2018-15982 is a use-after-free in the Flash’s file package com.adobe.tvsdk.mediacore.metadata that can be exploited to deliver and execute malicious code on a victim’s computer. It was flagged on November 29 by researchers with Gigamon Applied Threat Research (ATR) and Qihoo 360 … More →

    newswww.helpnetsecurity.comDec 6, 2018, 7:06 AM
  • Adobe released security updates for Flash Player that address two vulnerabilities, including a critical flaw, tracked as CVE-2018-15982, exploited in targeted attacks. Adobe fixed two flaws including a critical use-after-free bug, tracked as CVE-2018-15982, exploited by an advanced persistent threat actor aimed at a healthcare organization associated with the Russian presidential administration. The flaw could be exploited by […]

    newssecurityaffairs.comDec 5, 2018, 8:55 PM
  • Security updates released by Adobe on Wednesday for Flash Player patch two vulnerabilities, including a critical flaw exploited by a sophisticated threat actor in attacks aimed at a healthcare organization associated with the Russian presidential administration. The attack may be related to the recent Kerch Strait incident involving Russia and Ukraine.

    newswww.securityweek.comDec 5, 2018, 5:11 PM
  • For the past couple of years, Office documents have largely replaced exploit kits as the primary malware delivery vector, giving threat…

    newswww.malwarebytes.comDec 4, 2018, 5:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence