CVE-2013-5331
published 2013-12-11CVE-2013-5331: Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before…
PriorityP183critical9.3CVSS 2.0
AVNACMAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
72.50%
99.4th percentile
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote attackers to execute arbitrary code via crafted .swf content that leverages an unspecified "type confusion," as exploited in the wild in December 2013.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | < 3.9.0.1380 | 3.9.0.1380 |
| adobe | air_sdk | < 3.9.0.1380 | 3.9.0.1380 |
| adobe | flash_player | >= 11.0 < 11.7.700.257 | 11.7.700.257 |
| adobe | flash_player | >= 11.0 < 11.2.202.332 | 11.2.202.332 |
| adobe | flash_player | >= 11.8 < 11.8.800.175 | 11.8.800.175 |
| adobe | flash_player | >= 11.9 < 11.9.900.700 | 11.9.900.700 |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
\x64\xa1\x18\x00\x00\x00
- →Target delivery is via ActiveX Flash component in Internet Explorer (IE 6–10); look for Flash ActiveX CLSID {D27CDB6E-AE6D-11cf-96B8-444553540000} with LoadMovie method invocations in browser traffic. ↗
- →Exploit delivers a randomly named .swf file (4–6 random alpha characters) with Content-Type application/x-shockwave-flash and Pragma: no-cache headers; monitor HTTP responses matching this pattern. ↗
- →Post-exploitation uses automatic process migration (-f flag); monitor for Flash Player or IE child processes spawning unexpected new processes shortly after .swf delivery. ↗
- →Exploit targets Flash versions 11.7.x, 11.8.x, and 11.9.x prior to 11.9.900.170 on Windows; alert on these Flash version strings in User-Agent or plugin enumeration. ↗
- →Exploit is restricted to Windows + Internet Explorer user-agent combinations; cross-reference OS and browser fingerprint in HTTP headers to prioritize alerts. ↗
- ·The Metasploit module sets EXITFUNC to 'thread' and disables NOPs in the payload; shellcode analysis should account for the custom stack-adjustment stub prepended to the encoder rather than a standard NOP sled. ↗
- ·Exploitation was observed in the wild as early as November 2013, before the December 10 2013 disclosure date; in-the-wild samples may differ from the Metasploit module. ↗
- ·The blog post at malwaretracker.com documents AV-evasion techniques used by in-the-wild samples of CVE-2013-5331; signature-based detections may have low coverage against those variants. ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.3CRITICAL
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-57g5-r5h9-q5pf: Adobe Flash Player before 11
ghsa_unreviewed·2022-05-14
CVE-2013-5331 [HIGH] CWE-94 GHSA-57g5-r5h9-q5pf: Adobe Flash Player before 11
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote attackers to execute arbitrary code via crafted .swf content that leverages an unspecified "type confusion," as exploited in the wild in December 2013.
VulnCheck
Adobe Flash Player Improper Control of Generation of Code ('Code Injection')
vulncheck·2013·CVSS 9.3
CVE-2013-5331 [CRITICAL] Adobe Flash Player Improper Control of Generation of Code ('Code Injection')
Adobe Flash Player Improper Control of Generation of Code ('Code Injection')
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote attackers to execute arbitrary code via crafted .swf content that leverages an unspecified "type confusion," as exploited in the wild in December 2013.
Affected: Adobe Flash Player
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://nvd.nist.gov/vuln/detail/CVE-2013-5331; https://www.cve.org/CVERecord?id=CVE-2013-5331
Red Hat
flash-plugin: multiple code execution flaws (APSB13-28)
vendor_redhat·2013-12-10·CVSS 9.3
CVE-2013-5331 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-28)
flash-plugin: multiple code execution flaws (APSB13-28)
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote attackers to execute arbitrary code via crafted .swf content that leverages an unspecified "type confusion," as exploited in the wild in December 2013.
No detection rules found.
Exploit-DB
Adobe Flash Player - Type Confusion Remote Code Execution (Metasploit)
exploitdb·2014-04-29
CVE-2013-5331 Adobe Flash Player - Type Confusion Remote Code Execution (Metasploit)
Adobe Flash Player - Type Confusion Remote Code Execution (Metasploit)
---
##
# This module requires Metasploit: http//metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class Metasploit3 "Adobe Flash Player Type Confusion Remote Code Execution",
'Description' => %q{
This module exploits a type confusion vulnerability found in the ActiveX
component of Adobe Flash Player. This vulnerability was found exploited
in the wild in November 2013. This module has been tested successfully
on IE 6 to IE 10 with Flash 11.7, 11.8 and 11.9 prior to 11.9.900.170
over Windows XP SP3 and Windows 7 SP1.
},
'License' => MSF_LICENSE,
'Author' =>
[
'Unknown', # Vulnerability discovery and exploit in the wild
'bannedit', # Exploit in the wild disco
Metasploit
Adobe Flash Player Type Confusion Remote Code Execution
metasploit
Adobe Flash Player Type Confusion Remote Code Execution
Adobe Flash Player Type Confusion Remote Code Execution
This module exploits a type confusion vulnerability found in the ActiveX component of Adobe Flash Player. This vulnerability was found exploited in the wild in November 2013. This module has been tested successfully on IE 6 to IE 10 with Flash 11.7, 11.8 and 11.9 prior to 11.9.900.170 over Windows XP SP3 and Windows 7 SP1.
http://helpx.adobe.com/security/products/flash-player/apsb13-28.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-12/msg00008.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00075.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00084.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1818.htmlhttp://helpx.adobe.com/security/products/flash-player/apsb13-28.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-12/msg00008.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00075.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00084.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1818.html
2013-12-11
Published
Exploited in the wild