Junglewise Threat Intelligence

CVE-2014-0502: Adobe Flash Player Double Free Vulnerablity

CVE-2014-0502 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2024-09-17

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Flash Player and AIR contain a double free vulnerability that allows remote attackers to execute arbitrary code via unspecified vectors. The vulnerability was exploited in the wild as a zero-day prior to the release of patches.

Affected products

  • Adobe Flash Player before 11.7.700.269, 11.8.x through 12.0.x before 12.0.0.70 (Windows/Mac); before 11.2.202.341 (Linux)
  • Adobe AIR before 4.0.0.1628 (Android)
  • Adobe AIR SDK before 4.0.0.1628
  • Adobe AIR SDK & Compiler before 4.0.0.1628

Timeline

  • 2014-02: exploited: Exploited in the wild in February 2014.
  • 2014-02-20: patched: Adobe released security bulletin APSB14-07.
  • 2024-09-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats