EXPOSURES › CVE-2013-0643
CVE-2013-0643
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Flash Player's discontinued status leaves unpatched RCE vulnerabilities exploitable in legacy systems.
Adobe Flash Player reached end-of-life in December 2020 with no security patches, leaving installations perpetually vulnerable to remote code execution via crafted SWF content. DIB organizations must ensure no legacy Flash Player instances remain in production environments to avoid compliance violations and unpatched attack surfaces.
Shame score — The vendor discontinued the product without providing security updates, leaving known vulnerabilities unpatched and exploitable indefinitely.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |