CVE-2014-0537 is an access restriction bypass vulnerability affecting Adobe Flash Player on Windows, OS X, and Linux, as well as Adobe AIR and its SDKs across various platforms. With a CVSS score of 7.5, this vulnerability is easily exploitable over a network with no authentication required, potentially leading to partial compromise of confidentiality, integrity, and availability. While there is no known exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not listed in CISA's KEV catalog, it did receive some media attention at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 14.0.0.110CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air_sdk:*:*:*:*:*:*:*:* | ||
13.0.0.83CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air_sdk:13.0.0.83:*:*:*:*:*:*:* | ||
13.0.0.111CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air_sdk:13.0.0.111:*:*:*:*:*:*:* | ||
<= 13.0.0.223CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
13.0.0.182CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:13.0.0.182:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.