SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Alert: Adobe Flash Zero-Day RCE Vulnerability (CVE-2018-4878)

Alert: Adobe Flash Zero-Day RCE Vulnerability (CVE-2018-4878)

Feb 1, 2018By Shakeel Bhat2 min read

A new critical Adobe Flash Player zero-dayvulnerability reported in the wild. The vulnerability identifies as CVE-2018-4878  is actively believed to be being exploited against South Koreans. According to the South Korean Computer Emergency Response Team which discovered the zero-day, the zero-day is believed to be a Flash SWF file embedded in MS Word documents. However, an attacker just needs to convince a user to open a Microsoft Office document, web page, or a spam mail containing the Flash file and can take complete control of the underlying system. Moreover, it is known as RCE Vulnerability. A vulnerability management tool can detect this vulnerability.

By using a patch management solution, we can remediate this vulnerability.

Adobe has released an advisory (APSA18-01) acknowledging the existence of this critical RCE vulnerability CVE-2018-4878. According to Adobe,

Adobe is aware of a report that an exploit for CVE-2018-4878 exists in the wild, and is being used in limited, targeted attacks against Windows users. These attacks leverage Office documents with embedded malicious Flash content distributed via email. Adobe will address this vulnerability in a release planned for the week of February 5.

Affected versions of Adobe Flash Player by RCE vulnerability:

  • Flash Player versions 28.0.0.137 and earlier for Windows, Macintosh, and Linux.
  • Flash Player version  28.0.0.137 and earlier for Adobe Flash Player for Google Chrome.
  • Flash Player version 28.0.0.137 and earlier for Adobe Flash Player for Microsoft Edge and Internet Explorer 11 on Windows 10 and Windows 8.1.

Recommendation:

Until Adobe releases a security patch for the vulnerability employ in following temporary recommendations:

  • Implement Protected View for Office. Protected View opens a file marked as potentially unsafe in read-only mode.
  • Change Flash Player’s behavior prompting the user before playing SWF content.
  • Remove Adobe Flash Player if not required.
  • Do not open an unknown email attachment, links, office documents etc.
  • Do not download anything from unknown sources or sites.
  • Always use latest updates of antivirus programs, and enable real-time monitoring.

SecPod Saner detects these vulnerabilities and automatically fixes it by applying security updates (as soon as patches are avaialble). Download SanerNow and keep your systems updated and secure.

Featured Posts

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

CVE Research

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Sep 28, 2026