SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2013-0643

Adobe Flash Player Incorrect Default Permissions Vulnerability

KEVHIGH 8.8EPSS 10.5%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 8 October 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
10.53% probability · 96th percentile
CISA KEV
Listed 17 September 2024 · due 8 October 2024
Weakness
CWE-269
Affected
adobe/flash player · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation · opensuse/opensuse · suse/linux enterprise desktop
Source
psirt@adobe.com

CISA notes

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. https://www.adobe.com/products/flashplayer/end-of-life-alternative.html#eol-alternative-faq ; https://nvd.nist.gov/vuln/detail/CVE-2013-0643

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.