First published: Tue Nov 11 2014(Updated: )
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0588 and CVE-2014-8438.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player for Internet Explorer 11 | >=13.0<13.0.0.252 | |
Adobe Flash Player for Internet Explorer 11 | >=14.0<=14.0.0.179 | |
Adobe Flash Player for Internet Explorer 11 | >=15.0<15.0.0.223 | |
macOS Yosemite | ||
Microsoft Windows | ||
Adobe Flash Player for Internet Explorer 11 | >=11.0<11.2.202.418 | |
Linux Kernel | ||
Adobe AIR SDK and Compiler | <=15.0.0.356 | |
Adobe AIR | <=15.0.0.356 | |
Adobe AIR SDK & Compiler | <15.0.0.356 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0573 has a high severity rating, allowing attackers to execute arbitrary code.
To fix CVE-2014-0573, update Adobe Flash Player to version 13.0.0.253 or later, 14.x to 14.0.0.180 or later, or 15.x to 15.0.0.224 or later.
Adobe Flash Player versions before 13.0.0.252, 14.x before 14.0.0.180, and 15.x before 15.0.0.224 are affected by CVE-2014-0573.
Yes, Adobe AIR versions before 15.0.0.356 are also vulnerable to CVE-2014-0573.
CVE-2014-0573 impacts Windows, OS X, and Linux operating systems where affected versions of Adobe Flash Player and AIR are installed.