CVE-2013-5331 is a critical type confusion vulnerability in Adobe Flash Player and AIR, affecting Windows, macOS, and Linux versions. This flaw allows remote attackers to execute arbitrary code by tricking users into viewing specially crafted .swf content. With a CVSS score of 9.3, it presents a severe risk, enabling complete compromise of confidentiality, integrity, and availability with medium attack complexity. The vulnerability was actively exploited in the wild in December 2013, and public exploit code, including a Metasploit module, is available, despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0, < 11.7.700.257CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.8, < 11.8.800.175CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.9, < 11.9.900.700CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.2.202.332CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
< 3.9.0.1380CPE matchmatch criteria | cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.