CVE-2014-8439
published 2014-11-25CVE-2014-8439: Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293…
PriorityP186high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-06-15
Exploited in the wild
EPSS
20.01%
97.1th percentile
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 15.0.0.292 | — |
| adobe | air_sdk | <= 15.0.0.301 | — |
| adobe | air_sdk_compiler | < 15.0.0.302 | 15.0.0.302 |
| adobe | flash_player | <= 11.2.202.418 | — |
| adobe | flash_player | <= 15.0.0.223 | — |
| adobe | flash_player | <= 13.0.0.252 | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
SIDs: 29066, 31332, 33182, 33183, 33184, 33185, 33186, 33187, 33188
- →CVE-2014-8439 was actively exploited in-the-wild by the Angler Exploit Kit via drive-by-download / malvertising; monitor for exploit kit traffic patterns from the listed IPs and domains. ↗
- →Angler EK selectively served the Flash 0-day only to specific User Agents (Internet Explorer / Firefox on Windows 8 and below); Chrome-based or non-standard user agents were served different exploits. Filter/alert on Flash exploit delivery conditioned on IE/Firefox UA strings. ↗
- →Attack spike began January 20, 2015; correlate network logs around that date for connections to the listed Angler EK IPs. ↗
- ·The Snort SIDs listed (29066, 31332, 33182–33188) were current as of the post date (January 2015); verify against the latest Snort.org or Defense Center rule sets for updated signatures. ↗
- ·The domain list associated with the Angler EK campaign was compiled as of 1/23/2015 and rotated rapidly (daily); the static list has limited ongoing value without continuous updates. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w62w-9g5v-w3p4: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-13
CVE-2014-8439 [HIGH] CWE-119 GHSA-w62w-9g5v-w3p4: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.
OSV
CVE-2014-8439: Adobe Flash Player before 13
osv·2014-11-25·CVSS 8.8
CVE-2014-8439 [HIGH] CVE-2014-8439: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.
VulnCheck
Adobe Flash Player Dereferenced Pointer Vulnerability
vulncheck·2014·CVSS 8.8
CVE-2014-8439 [HIGH] CWE-119 Adobe Flash Player Dereferenced Pointer Vulnerability
Adobe Flash Player Dereferenced Pointer Vulnerability
Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution.
Affected: Adobe Flash Player
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Known Ransomware Campaign Use: Known
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.fireeye.com/blog/threat-research/2015/01/a_different_exploit.html; https://www2.fireeye.com/rs/848-DID-242/images/rpt_APT37.pdf; https://dl.acm.org/doi/pdf/10.1145/3465481.3465758; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-06-15
CISA
Adobe Flash Player Dereferenced Pointer Vulnerability
cisa·2022-05-25·CVSS 8.8
CVE-2014-8439 [HIGH] CWE-119 Adobe Flash Player Dereferenced Pointer Vulnerability
Vulnerability: Adobe Flash Player Dereferenced Pointer Vulnerability
Affected: Adobe Flash Player
Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution.
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-8439
Remediation Due Date: 2022-06-15
Red Hat
flash-plugin: hardening against a code execution flaw (APSB14-26)
vendor_redhat·2014-11-25·CVSS 8.8
CVE-2014-8439 [HIGH] flash-plugin: hardening against a code execution flaw (APSB14-26)
flash-plugin: hardening against a code execution flaw (APSB14-26)
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.
No detection rules found.
No public exploits indexed.
Talos
Flash 0-day Exploited by Angler Exploit Kit
blogs_talos·2015-01-23·CVSS 8.8
[HIGH] Flash 0-day Exploited by Angler Exploit Kit
## Flash 0-day Exploited by Angler Exploit Kit
This post was authored by Nick Biasini , Earl Carter and Jaeson Schultz
Flash has long been a favorite target among Exploit Kits (EK). In October 2014 the Angler EK was believed to be targeting a new Flash vulnerability . The bug that the Angler exploit kit was attempting to exploit had been “accidentally” patched by Adobe’s APSB14-22 update. According to F-Secure , the vulnerability that Angler was actually attempting to exploit was an entirely new bug, CVE-2014-8439 . The bug was severe enough that Adobe fixed it out-of-band.
Fast forward to January 2015. With the emergence of this new Flash 0-day bug , we have more evidence that the Angler Exploit Kit developers are actively working on discovering fresh bugs in Flash for themselves. The
Talos
Flash 0-day Exploited by Angler Exploit Kit
blogs_talos·2015-01-23·CVSS 8.8
CVE-2014-8439 [HIGH] Flash 0-day Exploited by Angler Exploit Kit
This post was authored by Nick Biasini, Earl Carter and Jaeson Schultz
Flash has long been a favorite target among Exploit Kits (EK). In October 2014 the Angler EK was believed to be targeting a new Flash vulnerability. The bug that the Angler exploit kit was attempting to exploit had been “accidentally” patched by Adobe’s APSB14-22 update. According to F-Secure, the vulnerability that Angler was actually attempting to exploit was an entirely new bug, CVE-2014-8439. The bug was severe enough that Adobe fixed it out-of-band.
Fast forward to January 2015. With the emergence of this new Flash 0-day bug, we have more evidence that the Angler Exploit Kit developers are actively working on discovering fresh bugs in Flash for themselves. The group is incorporating these exploits into the Angler
Krebs
Adobe Pushes Critical Flash Patch
blogs_krebs·2014-11-25·CVSS 8.8
[HIGH] Adobe Pushes Critical Flash Patch
For the second time this month, Adobe has issued a security update for its Flash Player software. New versions are available for Windows, Mac and Linux versions of Flash. The patch provides additional protection on a vulnerability that Adobe fixed earlier this year for which attackers appear to have devised unique and active exploits.
Adobe recommends users of the Adobe Flash Player desktop runtime for Windows and Macintosh update to v. 15.0.0.239 by visiting the Adobe Flash Player Download Center, or via the update mechanism within the product when prompted. Adobe Flash Player for Linux has been updated to v. 11.2.202.424.
According to Adobe, these updates provide additional hardening against CVE-2014-8439, which was fixed in a Flash patch that the company released in October 2014. The
Krebs
Adobe Pushes Critical Flash Patch – Krebs on Security
blogs_krebs·2014-11-01·CVSS 8.8
[HIGH] Adobe Pushes Critical Flash Patch – Krebs on Security
For the second time this month, Adobe has issued a security update for its Flash Player software. New versions are available for Windows , Mac and Linux versions of Flash. The patch provides additional protection on a vulnerability that Adobe fixed earlier this year for which attackers appear to have devised unique and active exploits.
Adobe recommends users of the Adobe Flash Player desktop runtime for Windows and Macintosh update to v. 15.0.0.239 by visiting the Adobe Flash Player Download Center, or via the update mechanism within the product when prompted. Adobe Flash Player for Linux has been updated to v. 11.2.202.424.
According to Adobe, these updates provide additional hardening against CVE-2014-8439, which was fixed in a Flash patch that the company released in October 2014 . Th
Bugzilla
CVE-2014-8439 flash-plugin: hardening against a code execution flaw (APSB14-26)
bugzilla·2014-11-26·CVSS 8.8
CVE-2014-8439 [HIGH] CVE-2014-8439 flash-plugin: hardening against a code execution flaw (APSB14-26)
CVE-2014-8439 flash-plugin: hardening against a code execution flaw (APSB14-26)
Adobe has released Flash Player 11.2.202.424 for Linux to correct the following flaw:
These updates provide additional hardening against a vulnerability in the handling of a dereferenced memory pointer that could lead to code execution (CVE-2014-8439). A mitigation was previously introduced for this issue in the October 14, 2014 release.
External References:
http://helpx.adobe.com/security/products/flash-player/apsb14-26.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2014:1915 https://rhn.redhat.com/errata/RHSA-2014-1915.html
http://helpx.adobe.com/security/products/flash-player/apsb14-22.htmlhttp://helpx.adobe.com/security/products/flash-player/apsb14-26.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-11/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-12/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1915.htmlhttp://secunia.com/advisories/60217http://www.securityfocus.com/bid/71289http://www.securitytracker.com/id/1031259https://exchange.xforce.ibmcloud.com/vulnerabilities/98932https://www.f-secure.com/weblog/archives/00002768.htmlhttp://helpx.adobe.com/security/products/flash-player/apsb14-22.htmlhttp://helpx.adobe.com/security/products/flash-player/apsb14-26.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-11/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-12/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1915.htmlhttp://secunia.com/advisories/60217http://www.securityfocus.com/bid/71289http://www.securitytracker.com/id/1031259https://exchange.xforce.ibmcloud.com/vulnerabilities/98932https://www.f-secure.com/weblog/archives/00002768.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-8439
2014-11-25
Published
2022-05-25
Added to CISA KEV
Exploited in the wild