CVE-2013-5331
EXPLOITED IN THE WILDAdobe Flash Player <11.7.700.257, 11.8.x, 11.9.x - RCE
Title source: llmDescription
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote attackers to execute arbitrary code via crafted .swf content that leverages an unspecified "type confusion," as exploited in the wild in December 2013.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/33095
metasploit
WORKING POC
NORMAL
by Unknown, bannedit, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/adobe_flash_filters_type_confusion.rb
References (5)
Scores
EPSS
0.8737
EPSS Percentile
99.4%
Exploitation Intel
VulnCheck KEV
2013-12-11
InTheWild.io
2018-12-13
Classification
CWE
CWE-94
Status
draft
Affected Products (3)
adobe/flash_player
< 11.7.700.257
adobe/air
< 3.9.0.1380
adobe/air_sdk
< 3.9.0.1380
Timeline
Published
Dec 11, 2013
Tracked Since
Feb 18, 2026