← Vulnerability feed

Vulnerability record · CVE-2013-0643 · published 27 February 2013

CVE-2013-0643: Adobe Flash Player Firefox sandbox privilege escalation

Adobe · Flash Player

Adobe Flash Player's Firefox sandbox does not properly restrict privileges, allowing crafted SWF content to escape the sandbox and run code with higher privileges. The flaw was exploited in the wild in February 2013 and affects Flash Player on Windows, Mac OS X and Linux.

8.8 CVSS 3.1 High CISA KEV since 17 Sep 2024 EPSS 11% · top 4.4% CWE-269 · Improper privilege management
8.8CVSS 3.1 base score, v2 9.3
11%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
8Affected product versions listed by NVD
11References
16 Jun 2026Last modified by NVD

Description

The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw allows remote code execution, is confirmed exploited in the wild and is in CISA KEV, but the product is end-of-life and requires user interaction to trigger.

What it is

Adobe Flash Player's Firefox sandbox does not properly restrict privileges, allowing crafted SWF content to escape the sandbox and run code with higher privileges. The flaw was exploited in the wild in February 2013 and affects Flash Player on Windows, Mac OS X and Linux.

Impact

An attacker who gets a victim to load a malicious SWF gains arbitrary code execution in the context of the browser process, bypassing the Flash sandbox.

Attack surface

Reached over the network via crafted SWF content rendered in a browser; the CVSS vector shows no privileges required but user interaction required, so the victim must load the malicious content.

Exploitation

Listed in CISA KEV since 2024-09-17 and described as exploited in the wild in February 2013; EPSS 30-day probability is about 10.5 percent (95th percentile).

What to do

  • Remove or disable Adobe Flash Player, which is end-of-life; CISA's required action is to discontinue use of the product.
  • If Flash cannot be removed immediately, apply the vendor fix referenced in Adobe bulletin APSB13-08 and the Red Hat, openSUSE and SUSE advisories.
  • Block Flash content and .swf downloads at the browser, proxy and email gateway.
  • Restrict browser use of legacy plugins and enforce click-to-play or plugin blocking.
  • Inventory endpoints and Linux distributions still carrying Flash packages and prioritize removal.

Detection

  • Hunt for Flash Player processes loading .swf content from untrusted or external sources.
  • Monitor for browser or plugin process spawning unexpected child processes or writing executables.
  • Alert on Flash Player versions below 10.3.183.67 or 11.6.602.171 (Windows/Mac) and 11.2.202.273 (Linux) where still present.
  • Review proxy and DNS logs for known exploit-hosting domains serving malicious SWF files.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2013-0643 to the Known Exploited Vulnerabilities catalog on 17 September 2024 as "Adobe Flash Player Incorrect Default Permissions Vulnerability". Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. Federal deadline 8 October 2024.

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-0643 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-5544OpenSLP heap out-of-bounds write in VMware ESXi and Horizon DaaSOpenSLP as shipped in VMware ESXi and Horizon DaaS contains a heap overwrite (out-of-bounds write) flaw. VMware rates it Critical with a maximum CVSS…KEVEPSS 97%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2016-1019Adobe Flash Player memory corruption allows code executionAdobe Flash Player 21.0.0.197 and earlier contains an unspecified memory corruption flaw that can crash the application or allow arbitrary code execu…KEVEPSS 22%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2013-0643), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.