Vulnerability record · CVE-2014-0497 · published 5 February 2014
CVE-2014-0497: Adobe Flash Player integer underflow allows remote code execution
Adobe · Flash Player
Adobe Flash Player contains an integer underflow (CWE-191) that allows remote attackers to execute arbitrary code via unspecified vectors. The flaw affects Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux. Because Flash Player is end-of-life, the exposure is severe wherever the plugin remains installed.
Description
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing, and EPSS near 1.0 indicate a remotely exploitable, actively exploited flaw with full system impact.
What it is
Adobe Flash Player contains an integer underflow (CWE-191) that allows remote attackers to execute arbitrary code via unspecified vectors. The flaw affects Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux. Because Flash Player is end-of-life, the exposure is severe wherever the plugin remains installed.
Impact
An attacker can execute arbitrary code in the context of the user running Flash Player, leading to full compromise of the affected system. Given the CVSS 3.1 score of 9.8, confidentiality, integrity, and availability impacts are all rated high.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges required (PR:N) and no user interaction required (UI:N) per the CVSS vector. In practice, reaching the flaw requires the victim to load attacker-controlled Flash content, but the record does not specify the exact delivery vector.
Exploitation
CVE-2014-0497 is listed in CISA KEV (added 2024-09-17) and has an EPSS 30-day probability of 0.99883 (99.964th percentile), indicating active exploitation and very high likelihood. No ransomware campaign use is documented in the record.
What to do
- Patch or remove Flash Player immediately; Adobe's advisory APSB14-04 covers the fixed versions (11.7.700.261, 12.0.0.44, 11.2.202.336).
- Because Flash Player is end-of-life, discontinue its use entirely per the CISA KEV required action.
- Remove or disable the Flash plugin from browsers and uninstall standalone Flash Player installations across Windows, macOS, and Linux systems.
- Apply vendor updates for bundled Flash in Chrome and Linux distributions (Red Hat, openSUSE, SUSE) referenced in the advisories.
- Block or restrict execution of Flash content (.swf) at the network and endpoint level where legacy dependencies remain.
Detection
- Hunt for Flash Player versions below 11.7.700.261, 12.0.0.44, or 11.2.202.336 on endpoints.
- Monitor for processes loading Flash Player libraries (e.g., NPSWF32.dll, libflashplayer.so) and for unexpected child processes spawned from browsers.
- Review proxy and DNS logs for retrieval of .swf content from untrusted or newly registered domains.
- Correlate endpoint telemetry for exploitation indicators such as anomalous memory writes or shellcode execution originating from Flash processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2014-0497 to the Known Exploited Vulnerabilities catalog on 17 September 2024 as "Adobe Flash Player Integer Underflow Vulnerablity". Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. Federal deadline 8 October 2024.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-0497 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-0497), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.