EXPOSURES › CVE-2014-0497
CVE-2014-0497
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Flash Player's integer underflow vulnerability enabled remote code execution and is actively exploited, posing a critical risk to legacy systems still in use.
Adobe Flash Player contained an integer underflow vulnerability allowing remote attackers to execute arbitrary code, and the product reached end-of-life in December 2020 with no further security patches. DIB organizations must immediately audit and remove any remaining Flash Player installations to avoid exploitation by active threat actors.
Shame score — The vendor shipped a discontinued product with a known, actively exploited RCE vulnerability that remains unpatched due to end-of-life status.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |