CVE-2014-4671

Description

Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
35.827

Associated Vulnerability

VulnerabilityOS Platform
Upgrade Adobe Air 14.0.0.110 to latest versionWindows
Upgrade Adobe flash player 14.0.0.125 to latest versionWindows
Vulnerabilities CVE-2014-0537,CVE-2014-0539,CVE-2014-4671 are affected in Adobe AIR 14.0.0.110Windows
Vulnerabilities CVE-2014-0537,CVE-2014-0539,CVE-2014-4671 are affected in Adobe Flash Player Plugin 14.0.0.125Windows
Vulnerabilities CVE-2014-0537,CVE-2014-0539,CVE-2014-4671 are affected in Adobe Flash Player PPAPI 14.0.0.125Windows
Multiple Vulnerabilities are affected in Adobe AIR 13.0.0.111Mac
Multiple Vulnerabilities are affected in Adobe AIR 13.0.0.83Mac
Multiple Vulnerabilities are affected in Adobe AIR 14.0.0.110Mac
Multiple Vulnerabilities are affected in Adobe AIR For Mac 13.0.0.111Mac
Multiple Vulnerabilities are affected in Adobe AIR For Mac 13.0.0.83Mac
Multiple Vulnerabilities are affected in Adobe AIR For Mac 14.0.0.110Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)
PATCH-601945Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234