Executive brief
A stack-based buffer overflow in Adobe Flash Player allows remote attackers to execute arbitrary code via unspecified vectors. The vulnerability was actively exploited in the wild starting in December 2014.
Affected products
- Adobe Systems Incorporated Flash Player before 13.0.0.259
- Adobe Systems Incorporated Flash Player 14.x
- Adobe Systems Incorporated Flash Player 15.x before 15.0.0.246
- Adobe Systems Incorporated Flash Player before 11.2.202.425 on Linux
Timeline
- 2014-12: exploited: Exploited in the wild in December 2014.
- 2022-04-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.