Executive brief
Adobe Flash Player and AIR contain a vulnerability in the handling of dereferenced memory pointers. Attackers can exploit this via unspecified vectors to execute arbitrary code or cause a denial of service.
Affected products
- Adobe Flash Player before 13.0.0.258, 14.x and 15.x before 15.0.0.239 (Windows/OS X); before 11.2.202.424 (Linux)
- Adobe AIR before 15.0.0.293
- Adobe AIR SDK before 15.0.0.302
- Adobe AIR SDK & Compiler before 15.0.0.302
Timeline
- 2014-11-25: disclosed: Initial vendor advisory APSB14-26 published
- 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-25: other: NVD publication date
- 2014-11-25: exploited: Reported as exploited in the wild in original advisory context