Junglewise Threat Intelligence

CVE-2013-0648: Adobe Flash Player Code Execution Vulnerability

CVE-2013-0648 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2024-09-17

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

An unspecified vulnerability in the ExternalInterface ActionScript functionality of Adobe Flash Player allows remote attackers to execute arbitrary code. Exploitation occurs when a user processes specially crafted SWF content.

Affected products

  • Adobe Systems Incorporated Flash Player before 10.3.183.67, 11.x before 11.6.602.171 (Windows/Mac); before 10.3.183.67, 11.x before 11.2.202.273 (Linux)

Timeline

  • 2013-02: exploited: Exploited in the wild in February 2013.
  • 2024-09-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats