Adobe Flash Player Code Execution Vulnerability

北京赛克艾威科技有限公司 2024-09-17


  • 漏洞编号:CVE-2013-0648
  • 漏洞等级:严重
  • 漏洞标签:Adobe、Flash Player、在野利用
  • 发布时间:2024-09-17

漏洞描述

Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content.

修复建议

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

参考链接

https://www.adobe.com/products/flashplayer/end-of-life-alternative.html#eol-alternative-faq ; https://nvd.nist.gov/vuln/detail/CVE-2013-0648

https://www.cisa.gov/known-exploited-vulnerabilities-catalog