CVE-2013-0648

Confirmed PUBLISHED

Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171...

Adobe · Flash Player
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.8 High

At a Glance

Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.

windows linux cisa macos nessus_scanner
CVE Published
Feb 27, 2013
Exploitation Reported
Sep 17, 2024
CVSS
8.8 High
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • RHSA-2013:0574 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2013-0574.html
  • SUSE-SU-2013:0373 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00035...
  • openSUSE-SU-2013:0359 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00025...
  • openSUSE-SU-2013:0360 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00026...
  • adobe.com/support/security/bulletins/apsb13-08.html adobe.com · CVE Record http://www.adobe.com/support/security/bulletins/apsb13-08.html

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.