Junglewise Threat Intelligence

CVE-2013-0643: Adobe Flash Player Incorrect Default Permissions Vulnerability

CVE-2013-0643 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2024-09-17

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox. Remote attackers can exploit this via crafted SWF content to bypass privilege restrictions and execute arbitrary code.

Affected products

  • Adobe Flash Player before 10.3.183.67, 11.x before 11.6.602.171 (Windows/Mac) and 11.x before 11.2.202.273 (Linux)

Timeline

  • 2013-02: exploited: Exploited in the wild in February 2013.
  • 2024-09-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats