CVE-2014-8439 is a critical vulnerability in Adobe Flash Player, AIR, AIR SDK, and AIR SDK & Compiler, affecting various versions across Windows, OS X, and Linux. This flaw allows attackers to execute arbitrary code or cause a denial of service through an invalid pointer dereference. With a CVSS score of 8.8 (High), it is easily exploitable over a network with low complexity, requiring user interaction, and can lead to complete compromise of confidentiality, integrity, and availability. This vulnerability has been actively exploited in the wild, as indicated by its presence in the CISA KEV catalog and mentions of exploit kits targeting it. Despite no public Metasploit or ExploitDB modules, it garnered significant community discussion and media coverage, highlighting its widespread impact and the urgency of patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.2.202.418CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 15.0.0.292CPE matchmatch criteria | cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:* | ||
<= 15.0.0.301CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:* | ||
< 15.0.0.302CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk_\&_compiler:*:*:*:*:*:*:*:* | ||
<= 15.0.0.223CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.