Skip to content
COOEY

EXPOSURES › CVE-2013-0648

CVE-2013-0648

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-09-17 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2013-0648 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatchedransomware

Adobe Flash Player's unpatched EOL status leaves remote code execution vulnerabilities perpetually exploitable.

Adobe Flash Player reached end-of-life in December 2020 with no security patches, leaving installations perpetually vulnerable to remote code execution via crafted SWF content. DIB organizations must ensure complete removal of Flash Player from all systems to avoid liability for unpatched, actively exploited vulnerabilities.

Shame score — The vendor discontinued the product without providing security updates, leaving installations perpetually vulnerable to remote code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized