CVE-2014-0539 is an access restriction bypass vulnerability affecting Adobe Flash Player on Windows, OS X, and Linux, as well as Adobe AIR and AIR SDK across various platforms. With a CVSS score of 7.5, this vulnerability is easily exploitable over the network with low complexity, potentially leading to partial compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, it garnered significant media attention, including a SecurityWeek article, though no public exploit code or Metasploit modules are currently available. Community discussion around this CVE is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 14.0.0.110CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:*:*:* | ||
13.0.0.83CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:13.0.0.83:*:*:*:*:*:*:* | ||
13.0.0.111CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air:13.0.0.111:*:*:*:*:*:*:* | ||
<= 14.0.0.110CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air_sdk:*:*:*:*:*:*:*:* | ||
13.0.0.83CPE matchmatch criteria | cpe:2.3:a:adobe:adobe_air_sdk:13.0.0.83:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.