CVE-2014-4671 is a vulnerability in Adobe Flash Player (before 13.0.0.231 and 14.x before 14.0.0.145 on Windows/OS X, before 11.2.202.394 on Linux) and Adobe AIR (before 14.0.0.137) that allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints. The vulnerability arises from improper restrictions on the SWF file format, enabling attackers to craft alphanumeric-only SWF files (using the Rosetta Flash tool) that can be reflected by JSONP endpoints and executed by Flash Player, bypassing Same Origin Policy and allowing exfiltration of sensitive data from authenticated sessions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit auxiliary module: 'flash_rosetta_jsonp_url_disclosure.rb'. The module targets CVE-2014-4671, a vulnerability in Adobe Flash Player (< 14.0.0.145) that can be exploited via specially crafted JSONP endpoints. The exploit works by spinning up a web server that serves a malicious SWF (Flash) file. When a victim with a vulnerable Flash version visits the attacker's server, the SWF abuses a JSONP endpoint (specified by the attacker) to steal the contents of specified same-domain URLs (also attacker-supplied) and exfiltrate them back to the attacker's server. The module requires the attacker to provide the vulnerable JSONP endpoint and the URLs to target. The exploit leverages both browser and network attack vectors, and the main payload is a compiled ActionScript SWF file encoded for alphanumeric delivery. The module also serves a permissive crossdomain.xml to enable Flash cross-origin requests. The repository is operational and ready for use within the Metasploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.