cbcvebase.
CVE-2014-8439
published 2014-11-25

CVE-2014-8439: Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293…

PriorityP186high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-06-15
Exploited in the wild
EPSS
20.01%
97.1th percentile
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.

Affected

6 ranges
VendorProductVersion rangeFixed in
adobeair<= 15.0.0.292
adobeair_sdk<= 15.0.0.301
adobeair_sdk_compiler< 15.0.0.30215.0.0.302
adobeflash_player<= 11.2.202.418
adobeflash_player<= 15.0.0.223
adobeflash_player<= 13.0.0.252

Detection & IOCsextracted from sources · hover to see the quote

hash1f6a4a3314b250e73a5649e2495ec131b27840d0948065f2a9c283a689a7b944
snort
SIDs: 29066, 31332, 33182, 33183, 33184, 33185, 33186, 33187, 33188
  • CVE-2014-8439 was actively exploited in-the-wild by the Angler Exploit Kit via drive-by-download / malvertising; monitor for exploit kit traffic patterns from the listed IPs and domains.
  • Angler EK selectively served the Flash 0-day only to specific User Agents (Internet Explorer / Firefox on Windows 8 and below); Chrome-based or non-standard user agents were served different exploits. Filter/alert on Flash exploit delivery conditioned on IE/Firefox UA strings.
  • Attack spike began January 20, 2015; correlate network logs around that date for connections to the listed Angler EK IPs.
  • ·The Snort SIDs listed (29066, 31332, 33182–33188) were current as of the post date (January 2015); verify against the latest Snort.org or Defense Center rule sets for updated signatures.
  • ·The domain list associated with the Angler EK campaign was compiled as of 1/23/2015 and rotated rapidly (daily); the static list has limited ongoing value without continuous updates.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.