Vulnerability record · CVE-2013-0643 · published 27 February 2013
CVE-2013-0643: Adobe Flash Player Firefox sandbox privilege escalation
Adobe · Flash Player
Adobe Flash Player's Firefox sandbox does not properly restrict privileges, allowing crafted SWF content to escape the sandbox and run code with higher privileges. The flaw was exploited in the wild in February 2013 and affects Flash Player on Windows, Mac OS X and Linux.
Description
The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows remote code execution, is confirmed exploited in the wild and is in CISA KEV, but the product is end-of-life and requires user interaction to trigger.
What it is
Adobe Flash Player's Firefox sandbox does not properly restrict privileges, allowing crafted SWF content to escape the sandbox and run code with higher privileges. The flaw was exploited in the wild in February 2013 and affects Flash Player on Windows, Mac OS X and Linux.
Impact
An attacker who gets a victim to load a malicious SWF gains arbitrary code execution in the context of the browser process, bypassing the Flash sandbox.
Attack surface
Reached over the network via crafted SWF content rendered in a browser; the CVSS vector shows no privileges required but user interaction required, so the victim must load the malicious content.
Exploitation
Listed in CISA KEV since 2024-09-17 and described as exploited in the wild in February 2013; EPSS 30-day probability is about 10.5 percent (95th percentile).
What to do
- Remove or disable Adobe Flash Player, which is end-of-life; CISA's required action is to discontinue use of the product.
- If Flash cannot be removed immediately, apply the vendor fix referenced in Adobe bulletin APSB13-08 and the Red Hat, openSUSE and SUSE advisories.
- Block Flash content and .swf downloads at the browser, proxy and email gateway.
- Restrict browser use of legacy plugins and enforce click-to-play or plugin blocking.
- Inventory endpoints and Linux distributions still carrying Flash packages and prioritize removal.
Detection
- Hunt for Flash Player processes loading .swf content from untrusted or external sources.
- Monitor for browser or plugin process spawning unexpected child processes or writing executables.
- Alert on Flash Player versions below 10.3.183.67 or 11.6.602.171 (Windows/Mac) and 11.2.202.273 (Linux) where still present.
- Review proxy and DNS logs for known exploit-hosting domains serving malicious SWF files.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2013-0643 to the Known Exploited Vulnerabilities catalog on 17 September 2024 as "Adobe Flash Player Incorrect Default Permissions Vulnerability". Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. Federal deadline 8 October 2024.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00025.html | Mailing List |
| http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00026.html | Mailing List |
| http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00035.html | Mailing List |
| http://rhn.redhat.com/errata/RHSA-2013-0574.html | Third Party Advisory |
| http://www.adobe.com/support/security/bulletins/apsb13-08.html | Broken LinkPatchVendor Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00025.html | Mailing List |
| http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00026.html | Mailing List |
| http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00035.html | Mailing List |
| http://rhn.redhat.com/errata/RHSA-2013-0574.html | Third Party Advisory |
| http://www.adobe.com/support/security/bulletins/apsb13-08.html | Broken LinkPatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0643 | US Government Resource |
Track CVE-2013-0643 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-0643), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.