Sploitus

Exploit for Use After Free in Adobe Flash Player

githubexploit Β· 2018-12-12

Exploit Code

README31 lines
## https://sploitus.com/exploit?id=9D86A1AE-388B-5A09-B717-474667040C6E
Credits
=========
- @Ridter https://github.com/Ridter/CVE-2018-15982_EXP
- @prsecurity https://github.com/prsecurity/CVE-2018-15982

Description
===========

Aggressor Script to launch an Internet Explorer driveby attack using CVE-2018-15982 exploit for Flash player.


Affected Product Versions
================

- Adobe Flash Player  Host CVE-2018-15982 Payload > Host
* Send link to victim or embed as part of other pages or a redirect
* Victim hits link with IE and outdated flash, you get a shell back in IE sandbox.


Demo
===========

![Alt text](./demo.gif)



CobaltStrike
============

* Load CVE-2018-15982.cna