CVE-2014-0502
Memory Safety in Adobe Flash Player ≤ 11.7.700.269
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HSummary
CVE-2014-0502 is a high-severity Double Free (CWE-415) vulnerability in Adobe Flash Player. Its CVSS base score is 8.8 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Client Execution (T1203); ranked in the top 2% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
The vulnerability is a double free flaw (CWE-415) present in Adobe Flash Player versions before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X, before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, and the corresponding AIR SDK and Compiler packages before 4.0.0.1628. It carries a CVSS 3.1 score of 8.8.
Remote attackers can exploit the issue via unspecified vectors to achieve arbitrary code execution on affected systems. The vulnerability was exploited in the wild in February 2014 and requires user interaction such as visiting a malicious page or opening a crafted document.
Adobe's APSB14-07 bulletin and related distribution advisories (openSUSE, Red Hat) recommend immediate upgrade to the fixed versions listed above. No other mitigations such as configuration changes are specified in the references.
The flaw saw active exploitation shortly after disclosure, underscoring the need for rapid patching of Flash and AIR installations.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2014-0533
Vulnerability Data
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR…
more
SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.
- CWE(s)
- KEV Date Added
- 17 September 2024
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
- 1 hardening rule · 1 OS baseline
—
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prevent double-free errors via static analysis, safe memory APIs, and testing.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing in development can detect double-free conditions before release.
Secure development life cycle includes memory-safety practices that can prevent double-free bugs.
Application security requirements can mandate memory-safety rules that reduce double-free risk.
Secure system architecture and engineering principles can prescribe safe memory-management patterns.
Secure coding standards directly address proper use of free() and similar functions.
Hardening callouts derived
Configuration rules from DISA STIG baselines that bear on weaknesses of the type cited by this CVE. Each rule is shown with the relationship its mapping actually records, against the CWE it was authored against. Derived via CVE→CWE over `controls_xwalks` (authoritative rows only; rows rated `none` are excluded).
Oracle Linux 8 (1 rule)
- V-248590 OL 8 must clear the page allocator to prevent use-after-free attacks. prevents CWE-415