CVE-2014-8442 describes a privilege escalation vulnerability in Adobe Flash Player, Adobe AIR, and related SDKs across Windows, OS X, and Linux platforms. This flaw allows an attacker to transition from a Low Integrity process to a Medium Integrity process due to incorrect permissions. With a CVSS score of 7.5, it is considered highly severe, enabling potential compromise of confidentiality, integrity, and availability with low attack complexity and no authentication required. While the vulnerability has garnered some community discussion and media coverage, there is no known active exploitation, nor are there publicly available exploit modules in common frameworks like Metasploit or Nuclei.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0, < 13.0.0.252CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 14.0, <= 14.0.0.179CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 15.0, < 15.0.0.223CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.2.202.418CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 15.0.0.356CPE matchmatch criteria | cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.