CVE-2014-0515

High PUBLISHED

Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356...

Adobe · Flash Player

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
10.0 High

At a Glance

Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.

windows metasploit linux
CVE Published
Apr 29, 2014
Exploitation Reported
Apr 29, 2014
CVSS
10.0 High
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • openSUSE-SU-2014:0585 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00017...
  • openSUSE-SU-2014:0589 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00000...
  • GLSA-201405-04 security.gentoo.org · Vendor Advisory http://security.gentoo.org/glsa/glsa-201405-04.xml
  • SUSE-SU-2014:0605 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00001...
  • RHSA-2014:0447 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2014-0447.html
Show 3 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.