CVE-2014-0497
KEVmassInteger Underflow Remote Code Execution in Adobe Flash Player
CISA: Adobe Flash Player Integer Underflow Vulnerablity
CVE-2014-0497 is an integer underflow (CWE-191) in Adobe Flash Player that allows a remote attacker to execute arbitrary code, triggered when the player processes specially crafted Flash content, such as that embedded in a malicious web page. Successful exploitation gives the attacker code execution on the victim system in the context of the Flash Player process. At the time of the 2014 disclosure, essentially every deployed Adobe Flash Player installation was potentially affected, making the population of exposed systems enormous, though Flash has since reached end-of-life and is no longer patched. CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2024-09-17, indicating confirmed in-the-wild exploitation; no public proof-of-concept is documented and ransomware association is listed as unknown. EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile), so any residual Flash deployment should be treated as high risk.
What to do: Because Adobe Flash Player is end-of-life/end-of-service and no longer receives security updates, CISA's required action is to discontinue use: uninstall Flash Player, disable or remove Flash plugins from browsers, and audit legacy Windows systems and intranet applications for residual Flash components. Since Flash is EOL, do not rely on patching alone — blocking SWF content delivery and removing the runtime are the durable mitigations; prioritize any systems that still render Flash from untrusted sources given the 99.9% EPSS score and KEV listing.
| Adobe Flash Player | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code.
- Affected
- Adobe Flash Player
- Required action
- The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
- Due date
- Ransomware use
- Unknown
- Vendors
- Adobe
- Products
- Flash Player
- Weakness
- CWE-191