CVE-2018-15982: Adobe Flash Player Use-After-Free Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2022-02-15. EPSS: 89.6% chance of exploitation in the next 30 days.

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Affected products

  • Adobe Flash Player: up to and including 31.0.0.153
  • Adobe Flash Player Installer: up to and including 31.0.0.108
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2019-01-18. Last modified 2026-10-01.