cbcvebase.
CVE-2014-0564
published 2014-10-15

CVE-2014-0564: Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293…

PriorityP272critical10CVSS 2.0
AVNACLAuNCCICAC
ITWVulnCheck KEV
Exploited in the wild
EPSS
6.19%
92.7th percentile
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0558.

Affected

69 ranges· showing 25
VendorProductVersion rangeFixed in
adobeadobe_air<= 15.0.0.252
adobeadobe_air<= 15.0.0.249
adobeadobe_air
adobeadobe_air
adobeadobe_air
adobeadobe_air
adobeadobe_air
adobeadobe_air
adobeadobe_air_sdk<= 15.0.0.249
adobeadobe_air_sdk
adobeadobe_air_sdk
adobeadobe_air_sdk
adobeadobe_air_sdk
adobeadobe_air_sdk
adobeair_desktop_runtime<= 15.0.0.249
adobeair_sdk<= 15.0.0.249
adobeair_sdk<= 15.0.0.252
adobeflash_player<= 13.0.0.244
adobeflash_player<= 11.2.202.406
adobeflash_player<= 15.0.0.152
adobeflash_player<= 15.0.0.167
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability involves a fixed-size stack variable 'cworkspace' used during RegExp compilation; when cworkspace is exhausted by repetitions of forward references, a heap expansion occurs but a stale local pointer is not updated, leading to out-of-bounds memory copy from stack into heap.
  • Heap Fengshui technique can be used to place a heap block adjacent to the stack, allowing the out-of-bounds copy to overwrite the length field of a Vector object, enabling arbitrary memory read/write — monitor for ActionScript Vector length manipulation following RegExp compilation.
  • Affected platforms are Adobe Flash Player on Windows XP and Windows 7; also affects Flash Player before 13.0.0.250 and 14.x/15.x before 15.0.0.189 on Windows/OS X, and before 11.2.202.411 on Linux.
  • ·CVE-2014-0564 is a memory corruption vulnerability distinct from CVE-2014-0558, though both are addressed in the same Adobe security bulletin (APSB14-22) and affect the same Flash Player version ranges.
  • ·The vulnerability exploitation relies on unspecified vectors per the official advisory; the PoC RegExp pattern is the only concrete trigger publicly documented.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.