CVE-2014-0502

Adobe Flash Player: Double Free Vulnerablity

As of , CVE-2014-0502 in Adobe Flash Player is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch soon.

Exploited
Yes: CISA listed it on 17 September 2024
US federal deadline
8 October 202421 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.25Higher than 97% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.41 on 17 September 2024EPSS on the day CISA listed it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
Vendor advice: www.adobe.comLinks below, from CISA's entry.

What CISA says to do

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CISA's required action

What the flaw is

Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code.

CISA's description

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.

The CVE record's description, from adobe

CVE published
21 February 2014
Assigned by
adobe
CVSS
8.8 High (CVSS 3.1, from CISA-ADP)
CWE-415
Double Free
CWE-399
Resource Management Errors
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Flash Player: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2014-0497Integer Underflow VulnerablityAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2010-1297Memory CorruptionAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry0.83
CVE-2011-0609UnspecifiedAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.64; verified Exploit-DB entry0.64
CVE-2012-0754Memory CorruptionAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.91; verified Exploit-DB entry0.91
CVE-2015-0311Remote Code ExecutionAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.86; verified Exploit-DB entry0.86
CVE-2015-0313Use-After-FreeAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.95; verified Exploit-DB entry0.95
CVE-2015-3113Heap-Based Buffer OverflowAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2015-5122Use-After-FreeAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.94; verified Exploit-DB entry0.94
CVE-2011-0611Remote Code ExecutionAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2012-1535Arbitrary Code ExecutionAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.70; verified Exploit-DB entry0.70

All 33 entries for Flash Player

Read further