Executive brief
Adobe Flash Player and AIR contain a double free vulnerability that allows remote attackers to execute arbitrary code via unspecified vectors. The vulnerability was exploited in the wild as a zero-day prior to the release of patches.
Affected products
- Adobe Flash Player before 11.7.700.269, 11.8.x through 12.0.x before 12.0.0.70 (Windows/Mac); before 11.2.202.341 (Linux)
- Adobe AIR before 4.0.0.1628 (Android)
- Adobe AIR SDK before 4.0.0.1628
- Adobe AIR SDK & Compiler before 4.0.0.1628
Timeline
- 2014-02: exploited: Exploited in the wild in February 2014.
- 2014-02-20: patched: Adobe released security bulletin APSB14-07.
- 2024-09-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.