CVE-2013-0643Active Exploitation(adobe / enterprise_linux_desktop)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch adobe enterprise_linux_desktop systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.

5.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-10-08. The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

Weakness type (CWE)
CWE-269

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux_desktop
  • enterprise_linux_eus
  • enterprise_linux_server
  • enterprise_linux_server_aus

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • 3 total mentions across 1 day

Affected systems

Products
enterprise_linux_desktopenterprise_linux_eusenterprise_linux_serverenterprise_linux_server_ausenterprise_linux_workstationflash_playerlinux_enterprise_desktoplinux_kernelmac_os_xopensuse

8 versions affected across 11 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-01: 3Active Exploitation · 2026-05-01: 3Patch / Workaround · 2026-05-01: 1Technical Details · 2026-05-01: 205-01
Signal classification1 categories
Active Exploitation
3100.0%
Referenced assets1 URL
By indicator
Full discourse3 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2013-0643: CISA added CVE-2013-0643 (Adobe Flash Player) to KEV; Firefox sandbox permission flaw enables RCE via crafted SWF. Flash is EOL — discontinue use.

    Post summary

    CVE-2013-0643 is a known exploited flaw in Adobe Flash Player; it involves a Firefox sandbox permission issue that can lead to remote code execution via crafted SWF files, and the recommended mitigation is to discontinue Flash use as it is end-of-life.

    1000034
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    What happened CISA added CVE-2013-0643 to the Known Exploited Vulnerabilities (KEV) catalog on 2024-09-17, confirming in-the-wild exploitation of this flaw CISA KEV. The vulnerability is an incorrect default permissions issue in the Firefox sandbox for Adobe Flash Player…

    Post summary

    CISA confirmed that CVE‑2013‑0643 is actively exploited in the wild, labeling it a Known Exploited Vulnerability; the flaw involves incorrect default permissions within Firefox’s sandbox for Adobe Flash Player.

    1000027
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2013-0643-flash-player #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post signals that CVE‑2013‑0643 is actively exploited, though no additional technical or remedial information is provided.

    0000030
    152 followersView on X
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeflash_player---
OSapplemac_os_x---
OSlinuxlinux_kernel---
OSmicrosoftwindows---
OSopensuseopensuse11.4--
OSopensuseopensuse12.1--
OSredhatenterprise_linux_desktop6.0--
OSredhatenterprise_linux_eus5.9--
OSredhatenterprise_linux_eus6.4--
OSredhatenterprise_linux_server6.0--
OSredhatenterprise_linux_server_aus5.9--
OSredhatenterprise_linux_server_aus6.4--
OSredhatenterprise_linux_workstation6.0--
OSsuselinux_enterprise_desktop10--
OSsuselinux_enterprise_desktop11--

Explore more