CVE-2014-9163: Adobe Flash Player Stack-Based Buffer Overflow Vulnerability
Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in December 2014.
Other sources
Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If Adobe Flash Player (end-of-life) is still in use, disconnect it from the network (e.g., disable/remove network access) to mitigate the remote code execution risk.
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9163?
CVE-2014-9163 is classified as a high severity vulnerability due to its potential to allow attackers to execute arbitrary code.
How do I fix CVE-2014-9163?
To mitigate CVE-2014-9163, users should update Adobe Flash Player to a version that is 13.0.0.259 or higher, or 15.0.0.246 or higher.
Which versions of Adobe Flash Player are affected by CVE-2014-9163?
CVE-2014-9163 affects Adobe Flash Player versions prior to 13.0.0.259, all versions of 14.x, and before 15.0.0.246.
What platforms are impacted by CVE-2014-9163?
CVE-2014-9163 impacts Adobe Flash Player on Windows, OS X, and Linux systems.
Is there active exploitation of CVE-2014-9163?
Yes, CVE-2014-9163 was actively exploited in the wild as of December 2014.