Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2018-4878 PoC — Adobe Flash Player 安全漏洞

Source
Associated Vulnerability
Title: Adobe Flash Player 安全漏洞 (CVE-2018-4878)
Description:A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
Description
Aggressor Script to launch IE driveby for CVE-2018-4878
Readme
Author and Credits
==================
Author: Vincent Yiu (@vysecurity)

Credits:
   - @evi1cg: Helping me test and keep me motivated
   - @smgoreli: Original Calc.exe PoC
   - @kbandla: He knows, and I know. ;)

Disclaimer
==========
Developed to encourage more Aggressor script development. Use only in authorized penetration testing!

Description
===========

Aggressor Script to launch an Internet Explorer driveby attack using CVE-2018-4878 exploit for Shockwave Flash player versions before February 2018.

Usage:
======

Video Demonstration: <https://www.youtube.com/watch?v=JhUlOIEdq0s>

* Click Host > Host CVE-2018-4878 Payload > Host
* Send link to victim or embed as part of other pages or a redirect
* Victim hits link with IE and outdated flash, you get a shell back in IE sandbox.


CobaltStrike
============

* Load CVE-2018-4878.cna
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →