CVE-2018-15982 is a use-after-free vulnerability in Adobe Flash Player. It affects Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier. The flaw can be triggered through malicious Flash content, including SWF content rendered in a browser context or embedded through document-based delivery chains. Successful exploitation corrupts memory and allows arbitrary code execution on the target system. The vulnerability was widely incorporated into exploit kits including Fallout, Spelevo, Bottle, and Underminer, and was used in drive-by compromise chains to deliver malware such as information stealers, banking trojans, backdoors, and ransomware.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository provides a proof-of-concept exploit for CVE-2018-15982, a critical vulnerability in Adobe Flash Player. The main file, CVE_2018_15982.py, is a Python script that takes user-supplied x86 and x64 shellcode binaries (typically generated with msfvenom) and crafts a malicious SWF file (exploit.swf) that exploits the vulnerability. The script also generates an index.html file that embeds the SWF, enabling browser-based exploitation. The README provides usage instructions and a demonstration. The exploit enables arbitrary code execution on vulnerable systems, as shown by launching calc.exe or a reverse shell. The repository structure is straightforward: the Python exploit generator, a sample HTML page for delivery, a README, and a shell script for git operations. No hardcoded network endpoints are present; the payload is user-supplied. The attack vector is browser-based, targeting users who open the crafted HTML/SWF in a vulnerable Flash environment.
This repository contains a Cobalt Strike Aggressor Script (CVE-2018-15982.cna) that automates the generation and hosting of a drive-by browser exploit for CVE-2018-15982, a critical vulnerability in Adobe Flash Player (<= 31.0.0.153). The script creates both a malicious SWF file and an HTML file that embeds it, hosting them on a specified local host and port. The payload delivered is a PowerShell stager or stageless shell, providing the attacker with code execution in the context of Internet Explorer's sandbox when a vulnerable user visits the hosted page. The exploit is operational and designed for use within the Cobalt Strike framework, leveraging its payload generation and web hosting capabilities. The README provides usage instructions and affected product versions. No hardcoded external IPs or domains are present; the host and URI are configurable by the operator.
This repository contains a Python script (CVE_2018_15982.py) that generates a malicious SWF file exploiting CVE-2018-15982, a critical vulnerability in Adobe Flash Player. The script takes two shellcode binaries (x86 and x64, typically generated with msfvenom) as input and embeds them into a crafted SWF file (exploit.swf). It also generates an index.html file that embeds the SWF, facilitating delivery via a web browser. The exploit targets Windows systems running vulnerable versions of Adobe Flash Player. Successful exploitation results in arbitrary code execution, with the payload fully customizable by the attacker. The repository is structured with a single exploit script and a README providing usage instructions. No hardcoded network endpoints are present; the exploit is delivered via the generated files.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Adobe Flash Player vulnerability reportedly possibly exploited in campaigns associated with Egregor delivery.
An Adobe Flash Player vulnerability reportedly possibly exploited in campaigns associated with Egregor, according to the content.
A vulnerability listed as being used by Spelevo and Underminer exploit kits in drive-by download activity.
Adobe Flash Playerのリモートコード実行脆弱性。本文では、PseudoGateキャンペーンでSpelevo Exploit Kitがこの脆弱性を悪用し、最終的にマルウェアを取得・実行すると説明されている。
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.