CVE-2018-15982 is a use-after-free vulnerability in Adobe Flash Player affecting versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier. The flaw can be triggered through crafted Flash content and results in dereferencing memory after it has been freed. Successful exploitation can corrupt process memory and enable arbitrary code execution in the context of the Flash Player process. The vulnerability was reported as having been used in targeted attacks, including delivery through malicious documents embedding OLE objects to trigger the vulnerable Flash component.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository provides a proof-of-concept exploit for CVE-2018-15982, a critical vulnerability in Adobe Flash Player. The main file, CVE_2018_15982.py, is a Python script that takes user-supplied x86 and x64 shellcode binaries (typically generated with msfvenom) and crafts a malicious SWF file (exploit.swf) that exploits the vulnerability. The script also generates an index.html file that embeds the SWF, enabling browser-based exploitation. The README provides usage instructions and a demonstration. The exploit enables arbitrary code execution on vulnerable systems, as shown by launching calc.exe or a reverse shell. The repository structure is straightforward: the Python exploit generator, a sample HTML page for delivery, a README, and a shell script for git operations. No hardcoded network endpoints are present; the payload is user-supplied. The attack vector is browser-based, targeting users who open the crafted HTML/SWF in a vulnerable Flash environment.
This repository contains a Cobalt Strike Aggressor Script (CVE-2018-15982.cna) that automates the generation and hosting of a drive-by browser exploit for CVE-2018-15982, a critical vulnerability in Adobe Flash Player (<= 31.0.0.153). The script creates both a malicious SWF file and an HTML file that embeds it, hosting them on a specified local host and port. The payload delivered is a PowerShell stager or stageless shell, providing the attacker with code execution in the context of Internet Explorer's sandbox when a vulnerable user visits the hosted page. The exploit is operational and designed for use within the Cobalt Strike framework, leveraging its payload generation and web hosting capabilities. The README provides usage instructions and affected product versions. No hardcoded external IPs or domains are present; the host and URI are configurable by the operator.
This repository contains a Python script (CVE_2018_15982.py) that generates a malicious SWF file exploiting CVE-2018-15982, a critical vulnerability in Adobe Flash Player. The script takes two shellcode binaries (x86 and x64, typically generated with msfvenom) as input and embeds them into a crafted SWF file (exploit.swf). It also generates an index.html file that embeds the SWF, facilitating delivery via a web browser. The exploit targets Windows systems running vulnerable versions of Adobe Flash Player. Successful exploitation results in arbitrary code execution, with the payload fully customizable by the attacker. The repository is structured with a single exploit script and a README providing usage instructions. No hardcoded network endpoints are present; the exploit is delivered via the generated files.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Adobe Flash Player vulnerability reportedly possibly exploited in campaigns associated with Egregor delivery.
An Adobe Flash Player vulnerability used by APT37 in earlier campaigns via embedded OLE objects in HWP documents to trigger exploitation and continue payload delivery.
Adobe Flash Player flaw used by APT37 in a past campaign via HWP/OLE content to trigger follow-on malicious activity.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.