EXPOSURES › CVE-2018-4878
CVE-2018-4878
CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 95/100
ransomwarerceexploited-in-wild
Adobe Flash Player's use-after-free vulnerability allows for code execution and is actively exploited, despite the product's end-of-life status and lack of updates.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.60
Adobe's Flash Player vulnerability was widely recognized as a critical flaw enabling code execution, reflecting severe fallout for the vendor.
Severe vulnerability in Flash Player allowing code execution, widely condemned as a critical flaw.
"Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution."
Mentions multiple Adobe vulnerabilities including arbitrary code execution, but lacks specific focus on CVE-2018-4878.
"Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution."
No substantive coverage of CVE-2018-4878; page is unauthorized frame with redirect warning.
No coverage of CVE-2018-4878; focuses on 2026 Firefox/Chrome/Adobe/VMware updates.
No coverage of CVE-2018-4878; generic CVE database page.
AFFECTED FEDRAMP PRODUCTS · 8
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |