Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Flash Apsb13 08 | — | Upgrade to Adobe Flash Player version 10.3.183.67 for Mac OS XUpgrade to Adobe Flash Player version 10.3.183.67 for WindowsUpgrade to Adobe Flash Player version 10.3.183.67 for LinuxUpgrade to Adobe Flash Player version 11.6.602.171 for Mac OS XUpgrade to Adobe Flash Player version 11.2.202.273 for LinuxUpgrade to Adobe Flash Player version 11.6.602.171 for Windows | Mar 3, 2013 | Feb 26, 2013 |
| Freebsd | — | Upgrade linux-f10-flashplugin | Dec 10, 2025 | Feb 27, 2013 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Feb 26, 2013 |
| Suse | — | Upgrade flash-player-gnomeUpgrade flash-playerUpgrade flash-player-kde4 | Feb 17, 2015 | Feb 26, 2013 |
| Ubuntu | — | Upgrade adobe-flashpluginUpgrade flashplugin-nonfree | Nov 19, 2024 | Feb 27, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub