EXPOSURES › CVE-2014-0502
CVE-2014-0502
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Flash Player's unpatched double-free RCE vulnerability (CVE-2014-0502) remains exploitable due to the product's EOL status.
Adobe Flash Player's double-free vulnerability (CVE-2014-0502) enables remote arbitrary code execution and has been actively exploited, yet the product reached end-of-life in December 2020 with no security patches. DIB organizations must immediately audit for legacy Flash installations, as continued use exposes systems to ransomware and compliance violations under NIST 800-171 and FedRAMP requirements.
Shame score — Adobe's EOL status for Flash Player created a perpetual liability for unpatched RCE vulnerabilities that were actively exploited in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |