CVE-2013-0648: Adobe Flash Player Code Execution Vulnerability
Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content.
Other sources
Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Flash Player (Windows, Mac OS X)to a version that resolves this vulnerability.Fixed in 10.3.183.67 - Upgrade
Upgrade
Adobe Flash Player (Windows, Mac OS X)to a version that resolves this vulnerability.Fixed in 11.6.602.171 - Upgrade
Upgrade
Adobe Flash Player (Linux)to a version that resolves this vulnerability.Fixed in 10.3.183.67 - Upgrade
Upgrade
Adobe Flash Player (Linux)to a version that resolves this vulnerability.Fixed in 11.2.202.273 - Remove
Remove
Adobe Flash Playerfrom your environment.Discontinue utilization of the product.
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0648?
CVE-2013-0648 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2013-0648?
To remediate CVE-2013-0648, users should update Adobe Flash Player to the latest version released by Adobe.
What software is affected by CVE-2013-0648?
CVE-2013-0648 specifically affects Adobe Flash Player versions prior to 10.3.183.67 and between 11.0 and 11.6.602.171.
Can CVE-2013-0648 be exploited remotely?
Yes, CVE-2013-0648 can be exploited remotely through maliciously crafted SWF content.
What types of attacks are associated with CVE-2013-0648?
CVE-2013-0648 is associated with remote code execution attacks that can compromise affected systems.