CVE-2013-0648

Description

Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
54.669

Associated Vulnerability

VulnerabilityOS Platform
Upgrade Adobe flash player 11.6.602.168 to latest versionWindows
Vulnerabilities CVE-2013-0504,CVE-2013-0643,CVE-2013-0648 are affected in Adobe Flash Player Plugin 11.6.602.168Windows
Vulnerabilities CVE-2013-0504,CVE-2013-0643,CVE-2013-0648 are affected in Adobe Flash Player PPAPI 11.6.602.168Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234