CVE-2014-0554 is a critical access restriction bypass vulnerability affecting multiple versions of Adobe Flash Player, Adobe AIR, Adobe AIR SDK, and Adobe AIR SDK & Compiler across Windows, OS X, Linux, and Android platforms. With a CVSS score of 10.0, this vulnerability is easily exploitable over the network with low complexity, allowing an attacker to achieve complete compromise of confidentiality, integrity, and availability. While no public exploit code is readily available through common sources like Metasploit or ExploitDB, and it is not listed in CISA's KEV catalog, the vulnerability received significant media coverage at the time of its disclosure. Adobe released patches to address this issue, as highlighted by SecurityWeek.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 14.0.0.179CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:*:*:* | ||
13.0.0.83CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:13.0.0.83:*:*:*:*:*:*:* | ||
13.0.0.111CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:13.0.0.111:*:*:*:*:*:*:* | ||
14.0.0.110CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:14.0.0.110:*:*:*:*:*:*:* | ||
14.0.0.137CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:14.0.0.137:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.