CVE-2013-0643

Description

The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
57.879

Associated Vulnerability

VulnerabilityOS Platform
Upgrade Adobe flash player 11.6.602.168 to latest versionWindows
Vulnerabilities CVE-2013-0504,CVE-2013-0643,CVE-2013-0648 are affected in Adobe Flash Player Plugin 11.6.602.168Windows
Vulnerabilities CVE-2013-0504,CVE-2013-0643,CVE-2013-0648 are affected in Adobe Flash Player PPAPI 11.6.602.168Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234