CVE-2014-0569 is an integer overflow vulnerability in Adobe Flash Player, AIR, and AIR SDK, affecting various operating systems and products from Adobe, Apple, Google, Linux, Microsoft, and SUSE. This critical vulnerability, with a CVSS score of 9.3, allows unauthenticated attackers to execute arbitrary code remotely with medium attack complexity. Despite not being in the KEV catalog, it has an exceptionally high EPSS score of 0.89, indicating a significant likelihood of exploitation. Multiple exploit modules exist, including a Metasploit module, and it was actively exploited in the wild shortly after its patch, garnering substantial community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.2.202.406CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 13.0.0.244CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:extended_support:*:*:* | ||
<= 15.0.0.152CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 15.0.0.167CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer_10:*:* | ||
<= 15.0.0.167CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer_11:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.