CVE-2018-4937: Adobe Flash Player

High severity, CVSS 8.8. EPSS: 25.7% chance of exploitation in the next 30 days.

Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Affected products

  • Adobe Flash Player: up to and including 29.0.0.113
  • Adobe Flash Player Desktop Runtime: up to and including 29.0.0.113

Published 2018-05-19. Last modified 2026-06-17.