CVE-2014-0497: Adobe Flash Player Integer Underflow Vulnerablity
Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code.
Other sources
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue utilization of Adobe Flash Player because the impacted product is end-of-life (EoL) and/or end-of-service (EoS).
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0497?
CVE-2014-0497 has a critical severity rating as it allows remote code execution through an integer underflow vulnerability in Adobe Flash Player.
Which versions of Adobe Flash Player are affected by CVE-2014-0497?
Adobe Flash Player versions before 11.7.700.261, between 11.8.x and 12.0.x prior to 12.0.0.44 on Windows and Mac, and before 11.2.202.336 on Linux are affected by CVE-2014-0497.
How do I fix CVE-2014-0497?
To remediate CVE-2014-0497, update Adobe Flash Player to the latest version available.
Can CVE-2014-0497 be exploited remotely?
Yes, CVE-2014-0497 can be exploited remotely, allowing attackers to execute arbitrary code.
What platforms are impacted by CVE-2014-0497?
CVE-2014-0497 impacts Adobe Flash Player on Windows, Mac OS X, and Linux platforms.