CVE-2013-0643
Summary
| CVE | CVE-2013-0643 |
|---|---|
| State | PUBLISHED |
| Assigner | adobe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-02-27 00:55:01 UTC |
| Updated | 2026-04-21 20:57:32 UTC |
| Description | The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.105330000 probability, percentile 0.952740000 (date 2026-07-21)
CISA KEV: Listed on 2024-09-17; due 2024-10-08; ransomware use Unknown
Problem Types: NVD-CWE-noinfo | CWE-269 | n/a | CWE-269 CWE-269 Improper Privilege Management
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
CISA Known Exploited Vulnerability
| Vendor | Adobe |
|---|---|
| Product | Flash Player |
| Name | Adobe Flash Player Incorrect Default Permissions Vulnerability |
| Required Action | The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. |
| Notes | https://www.adobe.com/products/flashplayer/end-of-life-alternative.html#eol-alternative-faq ; https://nvd.nist.gov/vuln/detail/CVE-2013-0643 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Flash Player | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | N/a | affected n/a | Not specified |
| ADP | Adobe | Flash Player | affected 10.3.183.67 custom | Not specified |
| ADP | Adobe | Flash Player | affected 11.0 11.6.602.171 custom | Not specified |
| ADP | Adobe | Flash Player | affected 10.3.183.67 custom | Not specified |
| ADP | Adobe | Flash Player | affected 11.0 11.6.602.171 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] openSUSE-SU-2013:0359-1: critical: flash-player to 1 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Third Party Advisory |
| [security-announce] openSUSE-SU-2013:0360-1: critical: flash-player to 1 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List |
| Adobe – Security Bulletins: APSB13-08 – Security updates available for Adobe Flash Player | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Broken Link, Patch, Vendor Advisory |
| [security-announce] SUSE-SU-2013:0373-1: critical: Security update for f | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2024-09-17T00:00:00.000Z | CVE-2013-0643 added to CISA KEV |
There are currently no legacy QID mappings associated with this CVE.