CVE-2014-0554
published 2014-09-10CVE-2014-0554: Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on…
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.90%
93.4th percentile
Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to bypass intended access restrictions via unspecified vectors.
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_air | <= 14.0.0.179 | — |
| adobe | adobe_air | <= 14.0.0.178 | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air_sdk | <= 14.0.0.178 | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | flash_player | <= 13.0.0.241 | — |
| adobe | flash_player | <= 11.2.202.400 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
vendor_redhat·2014-09-09·CVSS 10.0
CVE-2014-0554 [CRITICAL] flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to bypass intended access restrictions via unspecified vectors.
GHSA
GHSA-257j-jj92-ccj5: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17
CVE-2014-0554 [HIGH] GHSA-257j-jj92-ccj5: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to bypass intended access restrictions via unspecified vectors.
OSV
CVE-2014-0554: Adobe Flash Player before 13
osv·2014-09-10·CVSS 10.0
CVE-2014-0554 [CRITICAL] CVE-2014-0554: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to bypass intended access restrictions via unspecified vectors.
No detection rules found.
No public exploits indexed.
HackerOne
Flash Local Sandbox Bypass
hackerone·2014-10-07·CVSS 10.0
CVE-2014-0554 [CRITICAL] Flash Local Sandbox Bypass
Flash Local Sandbox Bypass
Vulnerability already reported to adobe (issue 2833) and patched (CVE-2014-0554)
http://helpx.adobe.com/security/products/flash-player/apsb14-21.html
First of all, note that the Adobe Security Bulletin notes: 'Bas Venis and Masato Kinugawa' for the acknowledgement of this CVE. The poc I have reported to Adobe was my own work.
My poc (issue 2833) exploited a security vulnerability which enabled an attacker to read files on the user's local disk. Adobe's patch involved adding a user confirmation step when navigating the page with navigateToURL. Although this doesn't really fix the underlying cause of this issue. It does provide a pretty solid protection to a whole plethora of exploits using the same kind of attack vector (relying on network requests to transfer
Bugzilla
CVE-2014-0547 CVE-2014-0549 CVE-2014-0550 CVE-2014-0551 CVE-2014-0552 CVE-2014-0553 CVE-2014-0554 CVE-2014-0555 CVE-2014-0556 CVE-2014-0557 CVE-2014-0559 flash-plugin: multiple code execution or secur
bugzilla·2014-09-09·CVSS 10.0
CVE-2014-0547 [CRITICAL] CVE-2014-0547 CVE-2014-0549 CVE-2014-0550 CVE-2014-0551 CVE-2014-0552 CVE-2014-0553 CVE-2014-0554 CVE-2014-0555 CVE-2014-0556 CVE-2014-0557 CVE-2014-0559 flash-plugin: multiple code execution or secur
CVE-2014-0547 CVE-2014-0549 CVE-2014-0550 CVE-2014-0551 CVE-2014-0552 CVE-2014-0553 CVE-2014-0554 CVE-2014-0555 CVE-2014-0556 CVE-2014-0557 CVE-2014-0559 flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
Adobe has released Flash Player 11.2.202.406 for Linux to correct the following flaws:
* These updates resolve memory leakage vulnerabilities that could be used to bypass memory address randomization (CVE-2014-0557).
* These updates resolve a security bypass vulnerability (CVE-2014-0554).
* These updates resolve a use-after-free vulnerability that could lead to code execution (CVE-2014-0553).
* These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2014-0547, CVE-2014-0549, CVE-2014-0550, CVE-2014-0551, CVE-2014-0552, CV
http://helpx.adobe.com/security/products/flash-player/apsb14-21.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00021.htmlhttp://secunia.com/advisories/61089http://security.gentoo.org/glsa/glsa-201409-05.xmlhttp://www.securityfocus.com/bid/69697http://www.securitytracker.com/id/1030822https://exchange.xforce.ibmcloud.com/vulnerabilities/95824http://helpx.adobe.com/security/products/flash-player/apsb14-21.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00021.htmlhttp://secunia.com/advisories/61089http://security.gentoo.org/glsa/glsa-201409-05.xmlhttp://www.securityfocus.com/bid/69697http://www.securitytracker.com/id/1030822https://exchange.xforce.ibmcloud.com/vulnerabilities/95824
2014-09-10
Published