cbcvebase.
CVE-2014-0556
published 2014-09-10

CVE-2014-0556: Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux…

PriorityP185critical10CVSS 2.0
AVNACLAuNCCICAC
ITWEXPLOITVulnCheck KEVRansomware
Exploited in the wild
EPSS
84.30%
99.7th percentile
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0559.

Affected

53 ranges· showing 25
VendorProductVersion rangeFixed in
adobeadobe_air<= 14.0.0.178
adobeadobe_air<= 14.0.0.179
adobeadobe_air
adobeadobe_air
adobeadobe_air
adobeadobe_air
adobeadobe_air_sdk<= 14.0.0.178
adobeadobe_air_sdk
adobeadobe_air_sdk
adobeadobe_air_sdk
adobeadobe_air_sdk
adobeflash_player<= 13.0.0.241
adobeflash_player<= 11.2.202.400
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player

Detection & IOCsextracted from sources · hover to see the quote

pathdata/exploits/CVE-2014-0556/msf.swf
otherSig ID 36762 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2014-0556)
otherSig ID 36763 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2014-0556)
otherSig ID 36764 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2014-0556)
otherSig ID 36754 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2014-0556)
urlhttp://googleprojectzero.blogspot.com/2014/09/exploiting-cve-2014-0556-in-flash.html
urlhttp://malware.dontneedcoffee.com/2014/10/cve-2014-0556-adobe-flash-player.html
  • CVE-2014-0556 was actively included in the Nuclear Pack exploit kit to deliver CryptoWall 2.0 ransomware; monitor for exploit kit traffic patterns delivering SWF payloads.
  • The Metasploit exploit module serves a malicious SWF file with Content-Type 'application/x-shockwave-flash'; detect HTTP responses delivering .swf files with no-cache headers to browsers matching Windows 7 / IE user-agents.
  • The exploit targets the copyPixelsToByteArray method of the BitmapData object in Flash; look for SWF files invoking this method with anomalous ByteArray position values.
  • The Metasploit module targets Windows 7 SP1 (32-bit) with IE 8–11 and Flash versions 14.0.0.176, 14.0.0.145, 14.0.0.125, and 14.0.0.179; prioritize detection on these specific browser/Flash version combinations.
  • CryptoWall 2.0 payloads were delivered as .scr and .exe attachments in emails with fake invoice, fax, and voicemail themes; flag inbound email attachments with these extensions and naming patterns.
  • ·The Metasploit module's browser requirements restrict exploitation to Windows 7 with IE user-agent and Flash versions in the 14.x range; the module will not trigger against other OS/browser combinations.
  • ·The NVD entry provided (CVE-2014-0559) is a different but related heap-based buffer overflow vulnerability in Adobe Flash Player; do not conflate its affected version ranges with CVE-2014-0556.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.