CVE-2014-0557: Critical severity macromedia flash player vulnerability
Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0557?
The severity of CVE-2014-0557 is rated as critical, as it allows attackers to execute arbitrary code on affected systems.
How do I fix CVE-2014-0557?
To fix CVE-2014-0557, update your Adobe Flash Player and Adobe AIR to the latest versions provided by Adobe.
Which versions are affected by CVE-2014-0557?
CVE-2014-0557 affects Adobe Flash Player versions before 13.0.0.244, 14.x, and 15.x before 15.0.0.152, along with several versions of Adobe AIR.
Is CVE-2014-0557 exploitable on all operating systems?
CVE-2014-0557 is exploitable on Windows, OS X, and Linux systems, depending on the version of Adobe Flash Player or AIR being used.
What are the potential impacts of exploiting CVE-2014-0557?
Exploiting CVE-2014-0557 can lead to unauthorized remote code execution, potentially allowing an attacker full control of the affected system.