Vulnerability Name:

CVE-2014-0510 (CCN-92683)

Assigned:2013-12-20
Published:2014-03-13
Updated:2014-06-21
Summary:Heap-based buffer overflow in Adobe Flash Player 12.0.0.77 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Zeguang Zhao and Liang Chen during a Pwn2Own competition at CanSecWest 2014.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (REDHAT CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.0 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2014-0510

Source: CCN
Type: Adobe Web site
Flash Player

Source: CCN
Type: Adobe Product Security Bulletin APSB14-14
Security updates available for Adobe Flash Player

Source: CONFIRM
Type: UNKNOWN
http://helpx.adobe.com/security/products/flash-player/apsb14-14.html

Source: SUSE
Type: UNKNOWN
SUSE-SU-2014:0671

Source: CCN
Type: RHSA-2014-0496
Critical: flash-plugin security update

Source: REDHAT
Type: UNKNOWN
RHSA-2014:0496

Source: GENTOO
Type: UNKNOWN
GLSA-201406-08

Source: MISC
Type: UNKNOWN
http://twitter.com/thezdi/statuses/444262022444621824

Source: CCN
Type: Pwn2Own Web site
Pwn2Own results for Thursday (Day Two)

Source: MISC
Type: UNKNOWN
http://www.pwn2own.com/2014/03/pwn2own-results-thursday-day-two/

Source: BID
Type: UNKNOWN
66241

Source: CCN
Type: BID-66241
Adobe Flash Player and Adobe AIR CVE-2014-0510 Heap Based Buffer Overflow Vulnerability

Source: XF
Type: UNKNOWN
adobe-flash-cve20140510-bo(92683)

Source: CCN
Type: ZDI-14-130
(Pwn2Own) Adobe Flash Display Object Memory Corruption Remote Code Execution Vulnerability

Vulnerable Configuration:Configuration 1:
  • cpe:/a:adobe:flash_player:12.0.0.77:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:rhel_extras:6:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:rhel_extras:5:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:adobe:flash_player:12.0.0.77:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:flash_player:13.0.0.206:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:flash_player:11.2.202.356:*:*:*:*:*:*:*
  • AND
  • cpe:/o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_8:*:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_rt:-:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_8.1:-:-:-:*:-:-:x32:*
  • OR cpe:/a:google:chrome:34.0.1847.131:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20140510
    V
    CVE-2014-0510
    2021-06-25
    oval:org.mitre.oval:def:24298
    V
    Heap-based buffer overflow in Adobe Flash Player 12.0.0.77 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism
    2015-08-03
    oval:org.mitre.oval:def:25159
    P
    SUSE-SU-2014:0671-1 -- Security update for flash-player
    2014-09-08
    oval:org.mitre.oval:def:24229
    P
    ELSA-2014:0496: flash-plugin security update (Critical)
    2014-09-01
    oval:org.mitre.oval:def:24789
    P
    RHSA-2014:0496: flash-plugin security update (Critical)
    2014-06-30
    oval:com.redhat.rhsa:def:20140496
    P
    RHSA-2014:0496: flash-plugin security update (Critical)
    2014-05-14
    oval:com.ubuntu.precise:def:20140510000
    V
    CVE-2014-0510 on Ubuntu 12.04 LTS (precise) - medium.
    2014-03-27
    BACK
    adobe flash player 12.0.0.77
    adobe flash player 12.0.0.77
    adobe flash player 13.0.0.206
    adobe flash player 11.2.202.356
    microsoft windows server 2012
    microsoft windows 8 *
    microsoft windows rt -
    microsoft windows 8.1 - -
    google chrome 34.0.1847.131