SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2014-0497

Adobe Flash Player Integer Underflow Vulnerablity

KEVCRITICAL 9.8EPSS 99.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 8 October 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
99.88% probability · 100th percentile
CISA KEV
Listed 17 September 2024 · due 8 October 2024
Weakness
CWE-191
Affected
adobe/flash player · google/chrome · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation · opensuse/opensuse · suse/linux enterprise desktop
Source
psirt@adobe.com

CISA notes

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. https://www.adobe.com/products/flashplayer/end-of-life-alternative.html#eol-alternative-faq ; https://nvd.nist.gov/vuln/detail/CVE-2014-0497

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.