CVE-2014-8439

Confirmed PUBLISHED

Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before...

Adobe · Flash Player
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.8 High

At a Glance

Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.

linux windows cisa
CVE Published
Nov 25, 2014
Exploitation Reported
May 25, 2022
CVSS
8.8 High
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • openSUSE-SU-2014:1562 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00004...
  • SUSE-SU-2014:1545 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00001...
  • openSUSE-SU-2014:1508 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00020...
  • RHSA-2014:1915 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2014-1915.html
  • 60217 secunia.com · Third-Party Advisory http://secunia.com/advisories/60217
Show 6 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.