CVE detail
CVE-2018-5002
Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
Experts believe that the Windows kernel zero-day vulnerability fixed this week by Microsoft with its Patch Tuesday updates has been exploited by several threat actors, including a new group.
newswww.securityweek.comDec 12, 2018, 8:39 AM#Unit 42 slices and dices CVE-2018-5002, uncovering new #CHAINSHOT malware.
vendorunit42.paloaltonetworks.comSep 6, 2018, 8:00 PMCyber criminal organizations and state-sponsored hackers continue to use Exploit kits to compromise targets world worldwide if the use of Exploit kits is decreased across the recent months, some of them were improved by adding the code to exploit recently discovered Flash and Internet Explorer zero-day vulnerabilities. “Since both Flash and the VBScript engine are […]
newssecurityaffairs.comJun 14, 2018, 7:06 AMExploit kits (EKs) might not be as dominant as they were several years ago, but they continue to exist and most of them already adopted exploits for recently discovered Flash and Internet Explorer zero-day vulnerabilities.
newswww.securityweek.comJun 13, 2018, 3:50 PM- Exploit kits: Spring 2018 reviewMalwarebytes Labs
Since our last report on exploit kits, there have been some new developments with the wider adoption of the February Flash…
newswww.malwarebytes.comJun 11, 2018, 5:00 PM I have been on the road for a few weeks now and surprisingly the topic of discussion has predominantly been patch management. Why is patch such a prevalent topic? Patching responsibility As we near Patch Tuesday this month I wanted to share a few thoughts and observations with you all from my recent travels. Recently I attended RiskSec in New York, and last week I was at Infosecurity Europe. At RiskSec I had the pleasure … More →
newswww.helpnetsecurity.comJun 11, 2018, 11:45 AM- Security Affairs newsletter Round 166 – News of the weekSecurity Affairs
A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Let me inform you that my new book, “Digging in the Deep Web” is online Kindle Edition Paper Copy Once again thank you! Crooks included the code for CVE-2018-8174 IE Zero-Day in the RIG Exploit Kit Impervas […]
newssecurityaffairs.comJun 10, 2018, 4:57 AM - Adobe releases fix for actively exploited Flash Player zero-dayHelp Net Security
If you’re still using Flash Player, it’s time to update it again – and quickly: Adobe has just patched a critical zero day vulnerability (CVE-2018-5002) actively exploited in the wild. The attacks are “limited, targeted attacks against Windows users,” but updates (v30.0.0.113 for all platforms) are available for Adobe Flash Player for Windows, macOS, Linux and Chrome OS. About CVE-2018-5002 and the attacks It is a stack-based buffer overflow vulnerability that has been independently discovered … More →
newswww.helpnetsecurity.comJun 8, 2018, 4:34 PM - Adobe fixed the CVE-2018-5002 Flash Zero-Day exploited in targeted attacks in the Middle EastSecurity Affairs
Adobe has recently fixed several vulnerabilities, including the CVE-2018-5002 Flash Zero-Day exploited in targeted attacks in the Middle East Adobe has released security updates for Flash Player that address four vulnerabilities, including a critical issue (CVE-2018-5002) that has been exploited in targeted attacks mainly aimed at entities in the Middle East. The CVE-2018-5002 vulnerability, reported by researchers at […]
newssecurityaffairs.comJun 7, 2018, 2:17 PM [Updated] Security updates released by Adobe on Thursday for Flash Player patch four vulnerabilities, including a critical flaw that has been exploited in targeted attacks.
newswww.securityweek.comJun 7, 2018, 12:25 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2016-4155CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…
- CVE-2016-4154CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…
- CVE-2016-4153CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…
- CVE-2016-4152CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…
- CVE-2016-4151CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…
- CVE-2016-4150CVSS 8.8 · High
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unkno…