CVE-2014-0585: Code Injection
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2014-0577, CVE-2014-0584, CVE-2014-0586, and CVE-2014-0590.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0585?
CVE-2014-0585 is considered a critical vulnerability that can lead to remote code execution.
How do I fix CVE-2014-0585?
To fix CVE-2014-0585, upgrade Adobe Flash Player to the latest version that is unaffected by the vulnerability.
Which versions are affected by CVE-2014-0585?
CVE-2014-0585 affects Adobe Flash Player versions before 13.0.0.252 and 14.x and 15.x before 15.0.0.223, among others.
What impacts does CVE-2014-0585 have on my system?
CVE-2014-0585 can allow attackers to execute arbitrary code, potentially compromising system integrity.
Is Adobe AIR impacted by CVE-2014-0585?
Yes, Adobe AIR versions before 15.0.0.356 are also vulnerable to CVE-2014-0585.