CVE-2014-0497

Confirmed PUBLISHED

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before...

Adobe · Flash Player
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical

At a Glance

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.

metasploit windows cisa macos linux nessus_scanner
CVE Published
Feb 05, 2014
Exploitation Reported
Sep 17, 2024
CVSS
9.8 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
adobe
flash_player

0 to < 11.7.700.261

Affected
adobe
flash_player

12.0.0 to <= 12.0.0.44

Affected
adobe
flash_player

0 to < 11.7.700.261

Affected
adobe
flash_player

12.0.0 to <= 12.0.0.44

Affected
n/a
n/a

n/a

Affected

CVE References

  • SUSE-SU-2014:0221 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00006...
  • RHSA-2014:0137 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2014-0137.html
  • openSUSE-SU-2014:0203 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00001...
  • openSUSE-SU-2014:0197 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00000...
  • 56799 secunia.com · Third-Party Advisory http://secunia.com/advisories/56799
Show 11 more references
  • 56737 secunia.com · Third-Party Advisory http://secunia.com/advisories/56737
  • 56437 secunia.com · Third-Party Advisory http://secunia.com/advisories/56437
  • 56780 secunia.com · Third-Party Advisory http://secunia.com/advisories/56780
  • 56839 secunia.com · Third-Party Advisory http://secunia.com/advisories/56839
  • 33212 exploit-db.com · Exploit http://www.exploit-db.com/exploits/33212
  • 102849 osvdb.org · VDB Entry http://www.osvdb.org/102849
  • 65327 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/65327
  • 1029715 securitytracker.com · VDB Entry http://www.securitytracker.com/id/1029715
  • adobe-flash-cve20140497-code-exec(90884) exchange.xforce.ibmcloud.com · VDB Entry https://exchange.xforce.ibmcloud.com/vulnerabilities/90884
  • helpx.adobe.com/security/products/flash-player/apsb14-04.html helpx.adobe.com · CVE Record http://helpx.adobe.com/security/products/flash-player/apsb14-04.html
  • googlechromereleases.blogspot.com/2014/02/stable-channel-update.html googlechromereleases.blogspot.com · CVE Record http://googlechromereleases.blogspot.com/2014/02/stable-channel-updat...

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.