CVE-2014-4671: CSRF
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4671?
CVE-2014-4671 has a critical severity rating due to its potential to allow remote code execution.
How do I fix CVE-2014-4671?
To fix CVE-2014-4671, update Adobe Flash Player to version 13.0.0.231 or later, or 14.0.0.145 or later.
What systems are affected by CVE-2014-4671?
CVE-2014-4671 affects Adobe Flash Player versions prior to 13.0.0.231 and 14.x before 14.0.0.145 on various operating systems.
Can CVE-2014-4671 affect mobile devices?
Yes, CVE-2014-4671 can affect Adobe AIR on Android devices prior to version 14.0.0.137.
Is there a workaround for CVE-2014-4671?
Disabling Flash Player or using an alternative software solution are potential workarounds for CVE-2014-4671 until a patch is applied.