Skip to content
COOEY

EXPOSURES › CVE-2014-8439

CVE-2014-8439

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2014-8439 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Adobe Flash Player's dereferenced pointer vulnerability allowed remote code execution, exploited in the wild despite the product's end-of-life status.

Adobe Flash Player suffered a dereferenced pointer vulnerability enabling remote code execution, a flaw that persisted after the product reached end-of-life in December 2020. DIB organizations must care because unpatched, discontinued software remains a perpetual liability, especially when such vulnerabilities are actively exploited in the wild. The failure highlights the risk of relying on legacy systems that no longer receive security updates, leading to potential data breaches and compliance violations.

Shame score — Adobe continued shipping a product with known critical vulnerabilities after reaching end-of-life, and the flaw was actively exploited in the wild, demonstrating severe negligence and avoidable risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized