CVE-2014-9163
adobe flash player
Published 10 Dec 2014 · updated 17 Jun 2026 · Analyzed
7.8 High · CVSS 3.1, CISA ADP
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 13 Apr 2022, with a remediation deadline of 4 May 2022 for US federal agencies.
Required action: The impacted product is end-of-life and should be disconnected if still in use.
Description
Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in December 2014.
References
- helpx.adobe.com/security/products/flash-player/apsb14-27.html · Vendor Advisory
- github.com/cisagov/vulnrichment/issues/196 · Issue Tracking
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-9163 · US Government Resource