ZeroHour

CVE-2014-0497

KEVmass

Integer Underflow Remote Code Execution in Adobe Flash Player

CISA: Adobe Flash Player Integer Underflow Vulnerablity

CVSS
EPSS
100%p100
Published
KEV added
AI analysis

CVE-2014-0497 is an integer underflow (CWE-191) in Adobe Flash Player that allows a remote attacker to execute arbitrary code, triggered when the player processes specially crafted Flash content, such as that embedded in a malicious web page. Successful exploitation gives the attacker code execution on the victim system in the context of the Flash Player process. At the time of the 2014 disclosure, essentially every deployed Adobe Flash Player installation was potentially affected, making the population of exposed systems enormous, though Flash has since reached end-of-life and is no longer patched. CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2024-09-17, indicating confirmed in-the-wild exploitation; no public proof-of-concept is documented and ransomware association is listed as unknown. EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile), so any residual Flash deployment should be treated as high risk.

What to do: Because Adobe Flash Player is end-of-life/end-of-service and no longer receives security updates, CISA's required action is to discontinue use: uninstall Flash Player, disable or remove Flash plugins from browsers, and audit legacy Windows systems and intranet applications for residual Flash components. Since Flash is EOL, do not rely on patching alone — blocking SWF content delivery and removing the runtime are the durable mitigations; prioritize any systems that still render Flash from untrusted sources given the 99.9% EPSS score and KEV listing.

Affected
Adobe Flash Player
Estimated exposure
massHundreds of millions to ~1 billion+ installations at the time of disclosure; current exposure limited to unpatched legacy systems and unknown in count — Public browser market-share statistics showed Flash Player installed on roughly 90% of internet-connected desktops in 2014, but Flash reached end-of-life in December 2020, so today's exposure consists only of unpatched legacy systems, of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code.

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player
Required action
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Flash Player
Weakness
CWE-191

In the news