9.3

CVE-2013-0643

Warnung
The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Flash Player Version < 10.3.183.67
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version >= 11.0 < 11.6.602.171
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Flash Player Version >= 11.0 < 11.2.202.273
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Eus Version 5.9
Redhat ≫ Enterprise Linux Eus Version 6.4
Opensuse ≫ Opensuse Version 11.4
Opensuse ≫ Opensuse Version 12.1
Suse ≫ Linux Enterprise Desktop Version 10 Update sp4 SwEdition -
Suse ≫ Linux Enterprise Desktop Version 11 Update sp2

17.09.2024: CISA Known Exploited Vulnerabilities (KEV) Catalog

Adobe Flash Player Incorrect Default Permissions Vulnerability

Schwachstelle

Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content.

Beschreibung

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.53% 0.952
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00025.html
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00026.html
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00035.html
Mailing List
http://rhn.redhat.com/errata/RHSA-2013-0574.html
Third Party Advisory
http://www.adobe.com/support/security/bulletins/apsb13-08.html
Patch
Vendor Advisory
Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0643
US Government Resource