CVE-2013-0648Active Exploitation(adobe / enterprise_linux_desktop)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Patch adobe enterprise_linux_desktop systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.

5.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-10-08. The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux_desktop
  • enterprise_linux_eus
  • enterprise_linux_server
  • enterprise_linux_server_aus

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Products
enterprise_linux_desktopenterprise_linux_eusenterprise_linux_serverenterprise_linux_server_ausenterprise_linux_workstationflash_playerlinux_enterprise_desktoplinux_kernelmac_os_xopensuse

8 versions affected across 11 products

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-01: 4Active Exploitation · 2026-05-01: 3Patch / Workaround · 2026-05-01: 1Technical Details · 2026-05-01: 205-01
Signal classification2 categories
Active Exploitation
375.0%
Disclosure
125.0%
Referenced assets1 URL
By indicator
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2013-0648: RCE via crafted SWF abusing Flash ExternalInterface; CISA adds CVE-2013-0648 to KEV and directs full discontinuation of the EoL product.

    Post summary

    CISA has listed CVE-2013-0648 on its Known Exploited Vulnerabilities catalog, indicating real‑world exploitation; the flaw is a remote code execution via crafted SWF, and the advisory recommends discontinuing the end‑of‑life product.

    1000043
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    NVD and MITRE both record the vulnerability under CVE-2013-0648, with the concise description matching CISA’s summary of the exploitation path NVD entry MITRE CVE. Translation: if a system still renders or executes Flash SWF files, a malicious SWF can seize control.

    Post summary

    The post references CVE‑2013‑0648 as documented by NVD, MITRE, and CISA, describing that a malicious Flash SWF file can exploit systems still rendering the content to seize control.

    1000026
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    What happened CISA has added Adobe Flash Player CVE-2013-0648 to its Known Exploited Vulnerabilities (KEV) catalog, signaling confirmed exploitation in the wild CISA KEV. The entry’s required action is explicit: the impacted product is end-of-life/end-of-service and…

    Post summary

    CISA has categorized Adobe Flash Player CVE-2013-0648 as a known exploited vulnerability, confirming that it is actively being abused in the wild.

    1000033
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2013-0648-flash-player #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The linked research suggests that CVE‑2013‑0648 in Adobe Flash Player is being actively exploited in the wild, though no exploit code, patch, or technical details are supplied.

    0000033
    152 followersView on X
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeflash_player---
OSapplemac_os_x---
OSlinuxlinux_kernel---
OSmicrosoftwindows---
OSopensuseopensuse11.4--
OSopensuseopensuse12.1--
OSredhatenterprise_linux_desktop6.0--
OSredhatenterprise_linux_eus5.9--
OSredhatenterprise_linux_eus6.4--
OSredhatenterprise_linux_server6.0--
OSredhatenterprise_linux_server_aus5.9--
OSredhatenterprise_linux_server_aus6.4--
OSredhatenterprise_linux_workstation6.0--
OSsuselinux_enterprise_desktop10--
OSsuselinux_enterprise_desktop11--

Explore more