CVE-2014-0564
published 2014-10-15CVE-2014-0564: Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293…
PriorityP272critical10CVSS 2.0
AVNACLAuNCCICAC
ITWVulnCheck KEV
Exploited in the wild
EPSS
6.19%
92.7th percentile
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0558.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_air | <= 15.0.0.252 | — |
| adobe | adobe_air | <= 15.0.0.249 | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air_sdk | <= 15.0.0.249 | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | air_desktop_runtime | <= 15.0.0.249 | — |
| adobe | air_sdk | <= 15.0.0.249 | — |
| adobe | air_sdk | <= 15.0.0.252 | — |
| adobe | flash_player | <= 13.0.0.244 | — |
| adobe | flash_player | <= 11.2.202.406 | — |
| adobe | flash_player | <= 15.0.0.152 | — |
| adobe | flash_player | <= 15.0.0.167 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability involves a fixed-size stack variable 'cworkspace' used during RegExp compilation; when cworkspace is exhausted by repetitions of forward references, a heap expansion occurs but a stale local pointer is not updated, leading to out-of-bounds memory copy from stack into heap. ↗
- →Heap Fengshui technique can be used to place a heap block adjacent to the stack, allowing the out-of-bounds copy to overwrite the length field of a Vector object, enabling arbitrary memory read/write — monitor for ActionScript Vector length manipulation following RegExp compilation. ↗
- →Affected platforms are Adobe Flash Player on Windows XP and Windows 7; also affects Flash Player before 13.0.0.250 and 14.x/15.x before 15.0.0.189 on Windows/OS X, and before 11.2.202.411 on Linux. ↗
- ·CVE-2014-0564 is a memory corruption vulnerability distinct from CVE-2014-0558, though both are addressed in the same Adobe security bulletin (APSB14-22) and affect the same Flash Player version ranges. ↗
- ·The vulnerability exploitation relies on unspecified vectors per the official advisory; the PoC RegExp pattern is the only concrete trigger publicly documented. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v62p-hc6h-7mcr: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2014-0558 [CRITICAL] CWE-94 GHSA-v62p-hc6h-7mcr: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0564.
GHSA
GHSA-jmf8-xc29-2wm7: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2014-0564 [CRITICAL] GHSA-jmf8-xc29-2wm7: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0558.
OSV
CVE-2014-0558: Adobe Flash Player before 13
osv·2014-10-15·CVSS 10.0
CVE-2014-0558 [CRITICAL] CVE-2014-0558: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0564.
OSV
CVE-2014-0564: Adobe Flash Player before 13
osv·2014-10-15·CVSS 10.0
CVE-2014-0564 [CRITICAL] CVE-2014-0564: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0558.
VulnCheck
Adobe Flash Player Arbitrary Code Execution
vulncheck·2014·CVSS 10.0
CVE-2014-0564 [CRITICAL] Adobe Flash Player Arbitrary Code Execution
Adobe Flash Player Arbitrary Code Execution
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0558.
Affected: Adobe Flash Player
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://cisa.gov/news-events/alerts/2015/04/29/top-30-targeted-high-risk-vulnerabilities; https://www.us-cert.gov/ncas/alerts/TA15-119A
Red Hat
flash-plugin: multiple code execution flaws (APSB14-22)
vendor_redhat·2014-10-14·CVSS 10.0
CVE-2014-0558 [CRITICAL] flash-plugin: multiple code execution flaws (APSB14-22)
flash-plugin: multiple code execution flaws (APSB14-22)
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0564.
Red Hat
flash-plugin: multiple code execution flaws (APSB14-22)
vendor_redhat·2014-10-14·CVSS 10.0
CVE-2014-0564 [CRITICAL] flash-plugin: multiple code execution flaws (APSB14-22)
flash-plugin: multiple code execution flaws (APSB14-22)
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0558.
No detection rules found.
No public exploits indexed.
Qualys
US-CERT: Top 30 Vulnerabilities | Qualys
blogs_qualys·2015-05-01·CVSS 2.6
[LOW] US-CERT: Top 30 Vulnerabilities | Qualys
On April 29, 2015 US-CERT published TA15-119A which describes the Top 30 vulnerabilities that critical infrastructure organizations should focus on because they are under attack all the time. The list contains Windows, Internet Explorer, Adobe Software from Reader, Flash to Cold Fusion, Java from Oracle and others and is quite similar to the more generic set of software packages published by the German BSI last December.
Here is a list of the vulnerabilities in the advisory. I have reordered and optimized where possible for efficient scanning with Qualys, for example listing the most recent patch first to take advantage of superseding patches:
- Windows: MS14-060 for CVE-2014-4114, Qualys ID: 90979
- Internet Explorer: MS14-021 for CVE-2014-1776, Qualys ID: 100191
- MS14-012 for CVE-201
HackerOne
Adobe Flash Player Out-of-Bound Read/Write Vulnerability
hackerone·2015-03-11
Adobe Flash Player Out-of-Bound Read/Write Vulnerability
Adobe Flash Player Out-of-Bound Read/Write Vulnerability
I. Summary
Adobe Flash Player is prone to a vulnerability which leads to Out-of-Bound access of memory. During the compilation of a malformed regular expression, relevant operations would cause Out-of-Bound Read/Write of stack and heap memory. Successful exploits may allow an attacker to gain access to sensitive memory addresses information in the context of the user running the affected application, which could be used to bypass ASLR protection. Advanced Heap Fengshui techniques may even allow an attacker to rewrite stack or heap variable, resulting in arbitrary code execution in the context of the user running the affected application.
II. Description
Building RegExp Object via a malformed regular expression, such as:
var exp:Reg
Bugzilla
CVE-2014-0564 CVE-2014-0558 CVE-2014-0569 flash-plugin: multiple code execution flaws (APSB14-22)
bugzilla·2014-10-14·CVSS 10.0
CVE-2014-0564 [CRITICAL] CVE-2014-0564 CVE-2014-0558 CVE-2014-0569 flash-plugin: multiple code execution flaws (APSB14-22)
CVE-2014-0564 CVE-2014-0558 CVE-2014-0569 flash-plugin: multiple code execution flaws (APSB14-22)
Adobe has released Flash Player 11.2.202.411 for Linux to correct the following flaws:
* These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2014-0564, CVE-2014-0558).
* These updates resolve an integer overflow vulnerability that could lead to code execution (CVE-2014-0569).
External References:
http://helpx.adobe.com/security/products/flash-player/apsb14-22.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2014:1648 https://rhn.redhat.com/errata/RHSA-2014-1648.html
http://helpx.adobe.com/security/products/flash-player/apsb14-22.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00033.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1648.htmlhttp://secunia.com/advisories/61980http://www.securitytracker.com/id/1031019http://helpx.adobe.com/security/products/flash-player/apsb14-22.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00033.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1648.htmlhttp://secunia.com/advisories/61980http://www.securitytracker.com/id/1031019
2014-10-15
Published
Exploited in the wild