cbcvebase.
CVE-2013-5331
published 2013-12-11

CVE-2013-5331: Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before…

PriorityP183critical9.3CVSS 2.0
AVNACMAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
72.50%
99.4th percentile
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote attackers to execute arbitrary code via crafted .swf content that leverages an unspecified "type confusion," as exploited in the wild in December 2013.

Affected

6 ranges
VendorProductVersion rangeFixed in
adobeair< 3.9.0.13803.9.0.1380
adobeair_sdk< 3.9.0.13803.9.0.1380
adobeflash_player>= 11.0 < 11.7.700.25711.7.700.257
adobeflash_player>= 11.0 < 11.2.202.33211.2.202.332
adobeflash_player>= 11.8 < 11.8.800.17511.8.800.175
adobeflash_player>= 11.9 < 11.9.900.70011.9.900.700

Detection & IOCsextracted from sources · hover to see the quote

pathexploits/CVE-2013-5331/Exploit.swf
other{D27CDB6E-AE6D-11cf-96B8-444553540000}
bytes
\x64\xa1\x18\x00\x00\x00
  • Target delivery is via ActiveX Flash component in Internet Explorer (IE 6–10); look for Flash ActiveX CLSID {D27CDB6E-AE6D-11cf-96B8-444553540000} with LoadMovie method invocations in browser traffic.
  • Exploit delivers a randomly named .swf file (4–6 random alpha characters) with Content-Type application/x-shockwave-flash and Pragma: no-cache headers; monitor HTTP responses matching this pattern.
  • Post-exploitation uses automatic process migration (-f flag); monitor for Flash Player or IE child processes spawning unexpected new processes shortly after .swf delivery.
  • Exploit targets Flash versions 11.7.x, 11.8.x, and 11.9.x prior to 11.9.900.170 on Windows; alert on these Flash version strings in User-Agent or plugin enumeration.
  • Exploit is restricted to Windows + Internet Explorer user-agent combinations; cross-reference OS and browser fingerprint in HTTP headers to prioritize alerts.
  • ·The Metasploit module sets EXITFUNC to 'thread' and disables NOPs in the payload; shellcode analysis should account for the custom stack-adjustment stub prepended to the encoder rather than a standard NOP sled.
  • ·Exploitation was observed in the wild as early as November 2013, before the December 10 2013 disclosure date; in-the-wild samples may differ from the Metasploit module.
  • ·The blog post at malwaretracker.com documents AV-evasion techniques used by in-the-wild samples of CVE-2013-5331; signature-based detections may have low coverage against those variants.

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.3CRITICAL
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.