Vulnerability record · CVE-2013-0634 · published 8 February 2013
CVE-2013-0634: Adobe Flash Player memory corruption via crafted SWF content
Adobe · Flash Player
Adobe Flash Player contains a memory corruption flaw (CWE-119) reachable through crafted SWF content. The description states it was exploited in the wild in February 2013, and it affects multiple platform-specific versions across Windows, Mac OS X, Linux and Android. Because Flash content is routinely embedded in web pages, this is a remotely reachable code execution issue with a broad install base.
Description
Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on Linux, before 11.1.111.32 on Android 2.x and 3.x, and before 11.1.115.37 on Android 4.x allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, as exploited in the wild in February 2013.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote unauthenticated code execution with confirmed in-the-wild exploitation and a very high EPSS score, though the product is legacy and largely retired.
What it is
Adobe Flash Player contains a memory corruption flaw (CWE-119) reachable through crafted SWF content. The description states it was exploited in the wild in February 2013, and it affects multiple platform-specific versions across Windows, Mac OS X, Linux and Android. Because Flash content is routinely embedded in web pages, this is a remotely reachable code execution issue with a broad install base.
Impact
An attacker can execute arbitrary code in the context of the Flash Player process, or crash it to cause a denial of service. Successful code execution typically gives the attacker the privileges of the user running the browser or Flash runtime.
Attack surface
Reached remotely over the network by delivering a malicious SWF file, for example via a web page or embedded content. The CVSS vector (AV:N/AC:M/Au:N) indicates no authentication is required and that some user action, such as loading the page or file, is needed.
Exploitation
The description explicitly states the flaw was exploited in the wild in February 2013. It is not listed in CISA KEV, but EPSS is very high (0.776, 99.5th percentile), consistent with active historical exploitation.
What to do
- Apply the vendor patch per Adobe security bulletin APSB13-04 and update to the fixed Flash Player versions listed for each platform.
- Apply the referenced Linux distribution updates (Red Hat RHSA-2013-0243 and openSUSE advisories) where Flash is packaged by the OS vendor.
- If Flash cannot be patched or is no longer needed, disable or uninstall Flash Player and block SWF content at the browser and proxy level.
- Restrict browsing to trusted sites and enforce click-to-play for plug-in content to reduce exposure to malicious SWF files.
Detection
- Monitor for Flash Player process crashes or memory corruption events, which may indicate exploitation attempts.
- Inspect proxy, IDS and web logs for SWF file downloads from untrusted or newly registered domains.
- Hunt for suspicious child processes spawned by browser or Flash Player processes, a common post-exploitation pattern.
- Review endpoint telemetry for anomalous behavior originating from the Flash Player process, such as unexpected network connections or file writes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00004.html | Mailing ListThird Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00006.html | Mailing ListThird Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00007.html | Mailing ListThird Party Advisory |
| http://rhn.redhat.com/errata/RHSA-2013-0243.html | Third Party Advisory |
| http://www.adobe.com/support/security/bulletins/apsb13-04.html | PatchVendor Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00004.html | Mailing ListThird Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00006.html | Mailing ListThird Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00007.html | Mailing ListThird Party Advisory |
| http://rhn.redhat.com/errata/RHSA-2013-0243.html | Third Party Advisory |
| http://www.adobe.com/support/security/bulletins/apsb13-04.html | PatchVendor Advisory |
Track CVE-2013-0634 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-0634), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.