CVE-2014-0497
Description
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.
In plain language
AI Act nowCVE-2014-0497 is a critical Flash Player bug that lets remote attackers run code without needing a click—so if you still have vulnerable Flash Player installed and running, you should act immediately.
CVE-2014-0497 is an unauthenticated remote code execution issue in Adobe Flash Player caused by an integer underflow (CWE-191) in affected versions; it is listed in the CISA KEV and has known public exploits.
What to do now
- Check whether Adobe Flash Player is installed and currently being used on any business PCs or servers (including via web browsers like Google Chrome).
- If any machines have vulnerable Flash Player versions, stop using them and plan an urgent upgrade to the fixed versions: Adobe Flash Player 11.2.202.336 (Linux) and the vendor’s fixed updates for Windows/macOS.
- For systems using Google Chrome, update Chrome to at least 32.0.1700.107.
- If you can’t upgrade immediately, remove/disable Adobe Flash Player and block Flash content in browsers until you can apply the fixes.
- Verify the update took effect on each device and repeat the check after any browser or software updates.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2014-0497 and every CVE in our database. Create a free account — no credit card required.
Create Free Account