SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2013-0648

Adobe Flash Player Code Execution Vulnerability

KEVHIGH 8.8EPSS 11.1%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 8 October 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
11.09% probability · 96th percentile
CISA KEV
Listed 17 September 2024 · due 8 October 2024
Affected
adobe/flash player · opensuse/opensuse · suse/linux enterprise desktop · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation
Source
psirt@adobe.com

CISA notes

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. https://www.adobe.com/products/flashplayer/end-of-life-alternative.html#eol-alternative-faq ; https://nvd.nist.gov/vuln/detail/CVE-2013-0648

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.