CVE-2014-0497Active Exploitation(adobe / chrome)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (6 mentions)

Immediate actions

  • Prioritize remediation for adobe chrome systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-10-08. The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

Weakness type (CWE)
CWE-191

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • chrome_os
  • enterprise_linux_desktop
  • enterprise_linux_eus

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC and exploit tooling are both present
  • 6 mentions across 1 observed day

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • 6 total mentions across 1 day

Affected systems

Products
chromechrome_osenterprise_linux_desktopenterprise_linux_eusenterprise_linux_serverenterprise_linux_server_ausenterprise_linux_workstationflash_playerlinux_enterprise_desktoplinux_kernel

8 versions affected across 14 products

Deep dive

Activity timeline6 mentions / 1d
02356Mentions · 2026-05-01: 6PoC Mentioned / Linked · 2026-05-01: 1Exploit Tool / Code · 2026-05-01: 1Active Exploitation · 2026-05-01: 605-01
Signal classification1 categories
Active Exploitation
6100.0%
Referenced assets1 URL
By indicator
Full discourse6 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:14 UTC: Thread live on @lyrie_ai. What happened CISA added CVE-2014-0497 to the Known Exploited Vulnerabilities catalog on 2024-09-17, signaling confirmed in-the-wild exploitation CISA KEV.

    Post summary

    CISA confirmed CVE-2014-0497 is actively exploited in the wild, as indicated by its inclusion in the Known Exploited Vulnerabilities catalog.

    2000034
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    03:00 UTC: First exploit attempt in the wild. What happened CISA added CVE-2014-0497 to the Known Exploited Vulnerabilities catalog on 2024-09-17, signaling confirmed in-the-wild exploitation CISA KEV.

    Post summary

    CISA confirmed that CVE-2014-0497 is being exploited in the wild, marking the first reported attack attempts against it.

    1000034
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:03 UTC: Lyrie Sentinel flagged it. What happened CISA added CVE-2014-0497 to the Known Exploited Vulnerabilities catalog on 2024-09-17, signaling confirmed in-the-wild exploitation CISA KEV.

    Post summary

    CISA confirmed that CVE-2014-0497 is being exploited in the wild, adding it to the Known Exploited Vulnerabilities catalog.

    1000022
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:11 UTC: GPT-5 enrichment complete. 651 words. 3 citations. What happened CISA added CVE-2014-0497 to the Known Exploited Vulnerabilities catalog on 2024-09-17, signaling confirmed in-the-wild exploitation CISA KEV.

    Post summary

    CISA has added CVE-2014-0497 to its Known Exploited Vulnerabilities catalog, confirming it is being exploited in the wild.

    1000029
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2014-0497 disclosed. CISA: CVE-2014-0497 added to Known Exploited Vulnerabilities — Adobe Flash Player What happened CISA added CVE-2014-0497 to the Known Exploited Vulnerabilities catalog on 2024-09-17, signaling confirmed in-the-wild exploitation CISA KEV.

    Post summary

    CISA has listed CVE-2014-0497 in its Known Exploited Vulnerabilities catalog, confirming that Adobe Flash Player has been actively exploited in the wild.

    1000029
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2014-0497-flash-player #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The article highlights that CVE‑2014‑0497 in Flash Player is being actively exploited, providing a PoC/exploit, but does not discuss patches or detailed technical aspects.

    0000032
    152 followersView on X
CPE platform detail21 entries

21 of 21 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeflash_player---
OSapplemac_os_x---
OSapplemacos---
Appgooglechrome---
OSgooglechrome_os---
OSlinuxlinux_kernel---
OSlinuxlinux_kernel---
OSmicrosoftwindows---
OSopensuseopensuse11.4--
OSopensuseopensuse12.3--
OSopensuseopensuse13.1--
OSredhatenterprise_linux_desktop5.0--
OSredhatenterprise_linux_desktop6.0--
OSredhatenterprise_linux_eus6.5--
OSredhatenterprise_linux_server5.0--
OSredhatenterprise_linux_server6.0--
OSredhatenterprise_linux_server_aus6.5--
OSredhatenterprise_linux_workstation5.0--
OSredhatenterprise_linux_workstation6.0--
OSsuselinux_enterprise_desktop11--
OSsuselinux_enterprise_desktop11--

Explore more