First published: Wed Sep 10 2014(Updated: )
Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow remote attackers to bypass the Same Origin Policy via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe AIR SDK | <=14.0.0.179 | |
Adobe AIR SDK | =13.0.0.83 | |
Adobe AIR SDK | =13.0.0.111 | |
Adobe AIR SDK | =14.0.0.110 | |
Adobe AIR SDK | =14.0.0.137 | |
Android | ||
Adobe AIR SDK | <=14.0.0.178 | |
Adobe AIR SDK | =13.0.0.83 | |
Adobe AIR SDK | =13.0.0.111 | |
Adobe AIR SDK | =14.0.0.110 | |
Adobe AIR SDK | =14.0.0.137 | |
Adobe Acrobat Reader | <=13.0.0.241 | |
Adobe Acrobat Reader | =13.0.0.182 | |
Adobe Acrobat Reader | =13.0.0.201 | |
Adobe Acrobat Reader | =13.0.0.206 | |
Adobe Acrobat Reader | =13.0.0.214 | |
Adobe Acrobat Reader | =13.0.0.223 | |
Adobe Acrobat Reader | =13.0.0.231 | |
Adobe Acrobat Reader | =14.0.0.125 | |
Adobe Acrobat Reader | =14.0.0.145 | |
Adobe Acrobat Reader | =14.0.0.176 | |
Adobe Acrobat Reader | =14.0.0.179 | |
Adobe Acrobat Reader | =15.0.0.144 | |
Apple iOS and macOS | ||
Microsoft Windows | ||
Adobe Acrobat Reader | <=11.2.202.400 | |
Adobe Acrobat Reader | =11.2.202.223 | |
Adobe Acrobat Reader | =11.2.202.228 | |
Adobe Acrobat Reader | =11.2.202.233 | |
Adobe Acrobat Reader | =11.2.202.235 | |
Adobe Acrobat Reader | =11.2.202.236 | |
Adobe Acrobat Reader | =11.2.202.238 | |
Adobe Acrobat Reader | =11.2.202.243 | |
Adobe Acrobat Reader | =11.2.202.251 | |
Adobe Acrobat Reader | =11.2.202.258 | |
Adobe Acrobat Reader | =11.2.202.261 | |
Adobe Acrobat Reader | =11.2.202.262 | |
Adobe Acrobat Reader | =11.2.202.270 | |
Adobe Acrobat Reader | =11.2.202.273 | |
Adobe Acrobat Reader | =11.2.202.275 | |
Adobe Acrobat Reader | =11.2.202.280 | |
Adobe Acrobat Reader | =11.2.202.285 | |
Adobe Acrobat Reader | =11.2.202.291 | |
Adobe Acrobat Reader | =11.2.202.297 | |
Adobe Acrobat Reader | =11.2.202.310 | |
Adobe Acrobat Reader | =11.2.202.332 | |
Adobe Acrobat Reader | =11.2.202.335 | |
Adobe Acrobat Reader | =11.2.202.336 | |
Adobe Acrobat Reader | =11.2.202.341 | |
Adobe Acrobat Reader | =11.2.202.346 | |
Adobe Acrobat Reader | =11.2.202.350 | |
Adobe Acrobat Reader | =11.2.202.356 | |
Adobe Acrobat Reader | =11.2.202.359 | |
Adobe Acrobat Reader | =11.2.202.378 | |
Adobe Acrobat Reader | =11.2.202.394 | |
Linux Kernel | ||
Adobe AIR SDK | <=14.0.0.178 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0548 has been assigned a high severity rating due to the potential for remote code execution.
To fix CVE-2014-0548, update Adobe Flash Player, Adobe AIR, or their SDKs to the latest versions provided by Adobe.
Adobe Flash Player versions before 13.0.0.244, 14.x and 15.x before 15.0.0.152, and earlier versions for Linux are affected by CVE-2014-0548.
Adobe AIR versions below 15.0.0.249 for Windows, OS X, and the AIR SDK are vulnerable to CVE-2014-0548.
Yes, CVE-2014-0548 can be exploited by malicious websites to execute arbitrary code on users' systems.