CVE-2013-5331

EXPLOITED IN THE WILD

Adobe Flash Player <11.7.700.257, 11.8.x, 11.9.x - RCE

Title source: llm

Description

Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote attackers to execute arbitrary code via crafted .swf content that leverages an unspecified "type confusion," as exploited in the wild in December 2013.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/33095
metasploit WORKING POC NORMAL
by Unknown, bannedit, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/adobe_flash_filters_type_confusion.rb

Scores

EPSS 0.8737
EPSS Percentile 99.4%

Exploitation Intel

VulnCheck KEV 2013-12-11
InTheWild.io 2018-12-13

Classification

CWE
CWE-94
Status draft

Affected Products (3)

adobe/flash_player < 11.7.700.257
adobe/air < 3.9.0.1380
adobe/air_sdk < 3.9.0.1380

Timeline

Published Dec 11, 2013
Tracked Since Feb 18, 2026