CVE-2014-8440: Critical severity macromedia flash player vulnerability
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0576, CVE-2014-0581, and CVE-2014-8441.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8440?
CVE-2014-8440 has a critical severity level as it allows attackers to execute arbitrary code.
How do I fix CVE-2014-8440?
To fix CVE-2014-8440, update Adobe Flash Player to version 13.0.0.253 or later, or upgrade to the latest supported version.
Which versions of Adobe Flash Player are affected by CVE-2014-8440?
CVE-2014-8440 affects Adobe Flash Player versions prior to 13.0.0.252, 14.x before 14.0.0.179, and 15.x before 15.0.0.223.
Is Adobe AIR affected by CVE-2014-8440?
Yes, CVE-2014-8440 affects Adobe AIR versions prior to 15.0.0.356.
What platforms are impacted by CVE-2014-8440?
CVE-2014-8440 impacts Windows, OS X, and Linux versions of Adobe Flash Player and Adobe AIR.