CVE-2013-5330
published 2013-11-13CVE-2013-5330: Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before…
PriorityP270critical10CVSS 2.0
AVNACLAuNCCICAC
ITWVulnCheck KEV
Exploited in the wild
EPSS
11.29%
95.5th percentile
Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5329.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | < 3.9.0.1210 | 3.9.0.1210 |
| adobe | air_sdk | < 3.9.0.1210 | 3.9.0.1210 |
| adobe | flash_player | >= 11.0 < 11.7.700.252 | 11.7.700.252 |
| adobe | flash_player | >= 11.0 < 11.2.202.327 | 11.2.202.327 |
| adobe | flash_player | >= 11.8 < 11.8.800.175 | 11.8.800.175 |
| adobe | flash_player | >= 11.9 < 11.9.900.152 | 11.9.900.152 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect Lurk exploit kit landing pages by matching URL paths against the regex pattern ^[A-Z0-9]{4}$ (four uppercase alphanumeric characters), effective for traffic from 2011–2013. ↗
- →Lurk served malicious content only once per IP address and limited targets to Russian/CIS IP ranges; single-hit exploit delivery from a given source IP is a behavioral indicator. ↗
- ·The sources describe Lurk's general exploit kit campaign (which exploited CVE-2013-5330 among other Flash vulnerabilities) but provide no file hashes, C2 IPs, or specific malicious domains directly tied to CVE-2013-5330 exploitation. IOCs extracted are campaign-level behavioral indicators, not CVE-specific artifacts. ↗
- ·The URL regex signature ^[A-Z0-9]{4}$ had an average TTL of two to three months, meaning it aged out quickly and may no longer be reliable for detecting current infrastructure. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jj82-mwc3-9h8h: Adobe Flash Player before 11
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-5329 [CRITICAL] CWE-119 GHSA-jj82-mwc3-9h8h: Adobe Flash Player before 11
Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5330.
GHSA
GHSA-j473-h6vv-fh38: Adobe Flash Player before 11
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-5330 [CRITICAL] CWE-119 GHSA-j473-h6vv-fh38: Adobe Flash Player before 11
Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5329.
VulnCheck
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2013·CVSS 10.0
CVE-2013-5330 [CRITICAL] Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5329.
Affected: Adobe Flash Player
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.helpnetsecurity.com/2014/02/11/older-flash-player-vulnerability-exploited
Red Hat
flash-plugin: multiple code execution flaws (APSB13-26)
vendor_redhat·2013-11-12·CVSS 10.0
CVE-2013-5330 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-26)
flash-plugin: multiple code execution flaws (APSB13-26)
Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5329.
Red Hat
flash-plugin: multiple code execution flaws (APSB13-26)
vendor_redhat·2013-11-12·CVSS 10.0
CVE-2013-5329 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-26)
flash-plugin: multiple code execution flaws (APSB13-26)
Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5330.
No detection rules found.
No public exploits indexed.
Trendmicro
Lurk: Retracing the Group’s Five-Year Campaign
blogs_trendmicro·2017-02-06
Lurk: Retracing the Group’s Five-Year Campaign
APT & Targeted Attacks
# Lurk: Retracing the Group’s Five-Year Campaign
The cybercriminal group Lurk was one of the first to effectively employ fileless infection techniques in large-scale attacks—techniques that arguably became staples for other malefactors.
By: Trend Micro
2017/02/06
Read time: ( words)
Save to Folio
By Fyodor Yarochkin and Vladimir Kropotov (Senior Threat Researchers)
Fileless infections are exactly what their namesake says: they're infections that don't involve malicious files being downloaded or written to the system’s disk. While fileless infections are not necessarily new or rare, it presents a serious threat to enterprises and end users given its capability to gain privileges and persist in the system of interest to an attacker—all while staying under the ra
Trendmicro
Lurk: Retracing the Group’s Five-Year Campaign
blogs_trendmicro·2017-02-06
Lurk: Retracing the Group’s Five-Year Campaign
APT & Targeted Attacks
## Lurk: Retracing the Group’s Five-Year Campaign
The cybercriminal group Lurk was one of the first to effectively employ fileless infection techniques in large-scale attacks—techniques that arguably became staples for other malefactors.
By: Trend Micro Feb 06, 2017 Read time: ( words)
Save to Folio
By Fyodor Yarochkin and Vladimir Kropotov (Senior Threat Researchers)
Fileless infections are exactly what their namesake says: they're infections that don't involve malicious files being downloaded or written to the system’s disk. While fileless infections are not necessarily new or rare, it presents a serious threat to enterprises and end users given its capability to gain privileges and persist in the system of interest to an attacker—all while staying under the
Trendmicro
Lurk: Retracing the Group’s Five-Year Campaign
blogs_trendmicro·2017-02-06
Lurk: Retracing the Group’s Five-Year Campaign
APT & Targeted Attacks
## Lurk: Retracing the Group’s Five-Year Campaign
The cybercriminal group Lurk was one of the first to effectively employ fileless infection techniques in large-scale attacks—techniques that arguably became staples for other malefactors.
By: Trend Micro 2017/02/06 Read time: ( words)
Save to Folio
By Fyodor Yarochkin and Vladimir Kropotov (Senior Threat Researchers)
Fileless infections are exactly what their namesake says: they're infections that don't involve malicious files being downloaded or written to the system’s disk. While fileless infections are not necessarily new or rare, it presents a serious threat to enterprises and end users given its capability to gain privileges and persist in the system of interest to an attacker—all while staying under the ra
Trendmicro
Lurk: Retracing the Group’s Five-Year Campaign
blogs_trendmicro·2017-02-06
Lurk: Retracing the Group’s Five-Year Campaign
APT y ataques dirigidos
## Lurk: Retracing the Group’s Five-Year Campaign
The cybercriminal group Lurk was one of the first to effectively employ fileless infection techniques in large-scale attacks—techniques that arguably became staples for other malefactors.
By: Trend Micro Feb 06, 2017 Read time: ( words)
Save to Folio
By Fyodor Yarochkin and Vladimir Kropotov (Senior Threat Researchers)
Fileless infections are exactly what their namesake says: they're infections that don't involve malicious files being downloaded or written to the system’s disk. While fileless infections are not necessarily new or rare, it presents a serious threat to enterprises and end users given its capability to gain privileges and persist in the system of interest to an attacker—all while staying under the
Trendmicro
Lurk: Retracing the Group’s Five-Year Campaign
blogs_trendmicro·2017-02-06
Lurk: Retracing the Group’s Five-Year Campaign
APT & attacchi mirati
## Lurk: Retracing the Group’s Five-Year Campaign
The cybercriminal group Lurk was one of the first to effectively employ fileless infection techniques in large-scale attacks—techniques that arguably became staples for other malefactors.
By: Trend Micro Feb 06, 2017 Read time: ( words)
Save to Folio
By Fyodor Yarochkin and Vladimir Kropotov (Senior Threat Researchers)
Fileless infections are exactly what their namesake says: they're infections that don't involve malicious files being downloaded or written to the system’s disk. While fileless infections are not necessarily new or rare, it presents a serious threat to enterprises and end users given its capability to gain privileges and persist in the system of interest to an attacker—all while staying under the r
Trendmicro
Lurk: Retracing the Group’s Five-Year Campaign
blogs_trendmicro·2017-02-06
Lurk: Retracing the Group’s Five-Year Campaign
APT und gezielte Angriffe
## Lurk: Retracing the Group’s Five-Year Campaign
The cybercriminal group Lurk was one of the first to effectively employ fileless infection techniques in large-scale attacks—techniques that arguably became staples for other malefactors.
By: Trend Micro Feb 06, 2017 Read time: ( words)
Save to Folio
By Fyodor Yarochkin and Vladimir Kropotov (Senior Threat Researchers)
Fileless infections are exactly what their namesake says: they're infections that don't involve malicious files being downloaded or written to the system’s disk. While fileless infections are not necessarily new or rare, it presents a serious threat to enterprises and end users given its capability to gain privileges and persist in the system of interest to an attacker—all while staying under t
Bugzilla
CVE-2013-5329 CVE-2013-5330 flash-plugin: multiple code execution flaws (APSB13-26)
bugzilla·2013-11-12·CVSS 10.0
CVE-2013-5329 [CRITICAL] CVE-2013-5329 CVE-2013-5330 flash-plugin: multiple code execution flaws (APSB13-26)
CVE-2013-5329 CVE-2013-5330 flash-plugin: multiple code execution flaws (APSB13-26)
Adobe has released Flash Player 11.2.202.327 for Linux to correct the following flaws:
* These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2013-5329, CVE-2013-5330).
External References:
http://www.adobe.com/support/security/bulletins/apsb13-26.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:1518 https://rhn.redhat.com/errata/RHSA-2013-1518.html
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00019.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1518.htmlhttp://www.adobe.com/support/security/bulletins/apsb13-26.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00019.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1518.htmlhttp://www.adobe.com/support/security/bulletins/apsb13-26.html
2013-11-13
Published
Exploited in the wild