cbcvebase.
CVE-2014-0569
published 2014-10-15

CVE-2014-0569: Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR…

PriorityP186critical9.3CVSS 2.0
AVNACMAuNCCICAC
ITWEXPLOITVulnCheck KEVRansomware
Exploited in the wild
EPSS
90.21%
99.8th percentile
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allows attackers to execute arbitrary code via unspecified vectors.

Affected

12 ranges
VendorProductVersion rangeFixed in
adobeair_desktop_runtime<= 15.0.0.249
adobeair_sdk<= 15.0.0.249
adobeair_sdk<= 15.0.0.252
adobeflash_player<= 11.2.202.406
adobeflash_player<= 13.0.0.244
adobeflash_player<= 15.0.0.152
adobeflash_player<= 15.0.0.167
adobeflash_player_desktop_runtime<= 15.0.0.167
opensuseevergreen
opensuseopensuse
opensuseopensuse
suselinux_enterprise_desktop

Detection & IOCsextracted from sources · hover to see the quote

pathdata/exploits/CVE-2014-0569/msf.swf
ip23.107.204.38
domainwww.newspot.kr
urlusers.qzone.qq.com/fcg-bin/cgi_get_portrait.fcg?uins=[QQ ID Number]
registryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL = http://127.0.0.1:[random]/[random]
  • The CVE-2014-0569 vulnerability is triggered via the casi32 method in Adobe Flash Player when a ByteArray of length 0 is set as domainMemory for the current application domain, causing an integer overflow.
  • Exploit delivery uses a SWF file served with Content-Type application/x-shockwave-flash; detect HTTP responses serving .swf files with Cache-Control: no-cache, no-store headers in exploit kit traffic.
  • KaiXin exploit kit delivered CVE-2014-0569 via malicious JavaScript from compromised websites or advertisements; monitor for KaiXin EK traffic patterns targeting Korean users.
  • KRBanker payload uses Process Hollowing to execute malicious code inside a clean PE from the System directory; monitor for suspicious memory writes into system processes.
  • KRBanker post-exploitation C2 registration uses HTTP GET to /ca.php with MAC address and code page parameters; detect this URI pattern in proxy/firewall logs.
  • KRBanker abuses Proxy Auto-Config (PAC) by setting AutoConfigURL registry key to localhost; detect creation of HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL pointing to 127.0.0.1.
  • KRBanker resolves pharming server IP by querying the QZone portrait API with a hardcoded QQ ID; detect outbound connections to users.qzone.qq.com/fcg-bin/cgi_get_portrait.fcg from non-browser processes.
  • The Metasploit module targets Windows 7 SP1 (32-bit) with IE 8–11 and Flash 15.0.0.167 specifically; use this to scope detection to vulnerable browser/Flash version combinations.
  • ·The Metasploit module's BrowserRequirements restrict exploitation to Flash version exactly 15.0.0.167; the actual CVE affects a broader range (Flash before 13.0.0.250 and 14.x/15.x before 15.0.0.189 on Windows/OS X, before 11.2.202.411 on Linux).
  • ·The pharming server IP (23.107.204.38) is dynamically retrieved from a QZone SNS profile nickname field and is not hardcoded in the malware; the IP may change frequently across KRBanker variants.

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vulncheck9.3CRITICAL
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.