CVE-2018-5002

Adobe Flash Player 29.0.0.171 and earlier versions

Published 9 Jul 2018 · updated 17 Jun 2026 · Analyzed

7.8 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 23 May 2022, with a remediation deadline of 13 Jun 2022 for US federal agencies.

Required action: The impacted product is end-of-life and should be disconnected if still in use.

Description

Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

References