First published: Wed Mar 12 2014(Updated: )
Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player for Internet Explorer 11 | >=11.0<11.2.202.346 | |
Linux Kernel | ||
Adobe Flash Player for Internet Explorer 11 | >=11.0<11.7.700.272 | |
Adobe Flash Player for Internet Explorer 11 | >=11.8<12.0.0.77 | |
macOS Yosemite | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-0503 is considered critical as it allows attackers to bypass the Same Origin Policy.
To fix CVE-2014-0503, update Adobe Flash Player to version 12.0.0.77 or later on affected platforms.
Adobe Flash Player versions prior to 11.7.700.272, versions 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and versions before 11.2.202.346 on Linux are affected.
CVE-2014-0503 impacts Windows, macOS, and Linux platforms running the affected versions of Adobe Flash Player.
Yes, CVE-2014-0503 can be exploited remotely, allowing attackers to manipulate the Same Origin Policy.