CVE-2014-8439: Adobe Flash Player Dereferenced Pointer Vulnerability
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.
Other sources
Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Flash Playerto a version that resolves this vulnerability.Fixed in 13.0.0.258 - Upgrade
Upgrade
Adobe Flash Player 14.xto a version that resolves this vulnerability.Fixed in 14.x - Upgrade
Upgrade
Adobe Flash Player 15.xto a version that resolves this vulnerability.Fixed in 15.0.0.239 - Upgrade
Upgrade
Adobe Flash Player (Linux)to a version that resolves this vulnerability.Fixed in 11.2.202.424 - Upgrade
Upgrade
Adobe AIRto a version that resolves this vulnerability.Fixed in 15.0.0.293 - Upgrade
Upgrade
Adobe AIR SDKto a version that resolves this vulnerability.Fixed in 15.0.0.302 - Upgrade
Upgrade
Adobe AIR SDK & Compilerto a version that resolves this vulnerability.Fixed in 15.0.0.302 - Compensating control
Because the impacted product is end-of-life, disconnect it if it is still in use.
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8439?
CVE-2014-8439 has a high severity rating because it allows attackers to execute arbitrary code on affected systems.
How do I fix CVE-2014-8439?
To remediate CVE-2014-8439, update Adobe Flash Player to version 13.0.0.258 or greater for Windows and OS X, or version 11.2.202.424 or greater for Linux.
Which versions of Adobe Flash Player are affected by CVE-2014-8439?
CVE-2014-8439 affects Adobe Flash Player versions before 13.0.0.258 on Windows and OS X and versions before 11.2.202.424 on Linux.
Is Adobe AIR affected by CVE-2014-8439?
Yes, Adobe AIR versions prior to 15.0.0.293 are affected by CVE-2014-8439.
What platforms are impacted by CVE-2014-8439?
CVE-2014-8439 impacts Windows, macOS, and Linux platforms running vulnerable versions of Adobe Flash Player and Adobe AIR.