Junglewise Threat Intelligence

CVE-2014-9163: Adobe Flash Player Stack-Based Buffer Overflow Vulnerability

CVE-2014-9163 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2022-04-13

Technologies: Adobe Systems Incorporated Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

A stack-based buffer overflow in Adobe Flash Player allows remote attackers to execute arbitrary code via unspecified vectors. The vulnerability was actively exploited in the wild starting in December 2014.

Affected products

  • Adobe Systems Incorporated Flash Player before 13.0.0.259
  • Adobe Systems Incorporated Flash Player 14.x
  • Adobe Systems Incorporated Flash Player 15.x before 15.0.0.246
  • Adobe Systems Incorporated Flash Player before 11.2.202.425 on Linux

Timeline

  • 2014-12: exploited: Exploited in the wild in December 2014.
  • 2022-04-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats