CVE-2013-0643
Adobe Flash Player Incorrect Default Permissions Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 8 October 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 10.53% probability · 96th percentile
- CISA KEV
- Listed 17 September 2024 · due 8 October 2024
- Weakness
- CWE-269
- Affected
- adobe/flash player · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation · opensuse/opensuse · suse/linux enterprise desktop
- Source
- psirt@adobe.com
CISA notes
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. https://www.adobe.com/products/flashplayer/end-of-life-alternative.html#eol-alternative-faq ; https://nvd.nist.gov/vuln/detail/CVE-2013-0643
References
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00025.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00026.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00035.htmlMailing List
- http://rhn.redhat.com/errata/RHSA-2013-0574.htmlThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb13-08.htmlBroken Link, Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00025.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00026.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00035.htmlMailing List
- http://rhn.redhat.com/errata/RHSA-2013-0574.htmlThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb13-08.htmlBroken Link, Patch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0643US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.