CVE-2014-0554: Critical severity adobe vulnerability
Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to bypass intended access restrictions via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0554?
CVE-2014-0554 has a CVSS score of 6.4, indicating a medium severity vulnerability.
How do I fix CVE-2014-0554?
To fix CVE-2014-0554, update Adobe Flash Player to versions 13.0.0.244 or later, 14.x versions to 15.0.0.152 or later, and Adobe AIR to 15.0.0.249 or later.
What products are affected by CVE-2014-0554?
CVE-2014-0554 affects Adobe Flash Player versions prior to 13.0.0.244, Adobe AIR prior to 15.0.0.249, and their related SDK versions.
Can CVE-2014-0554 be exploited remotely?
Yes, CVE-2014-0554 can be exploited remotely if a user views a malicious Flash file or web page.
What are the consequences of not addressing CVE-2014-0554?
Not addressing CVE-2014-0554 could lead to arbitrary code execution on vulnerable systems, putting sensitive data at risk.