Unpatched Vulnerability (0day) in Flash Player is being exploited by Angler EK

Discussion in 'other security issues & news' started by FleischmannTV, Jan 21, 2015.

  1. Compu KTed

    Compu KTed Registered Member

    Joined:
    Dec 18, 2013
    Posts:
    1,414
    I think Adobe should rename their flash -player to PATCH-PLAYER :)
     
  2. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,009
  3. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,009
  4. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    I think SIEVE-PLAYER is more appropriate. They never will be able to patch all the holes in it.
     
  5. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
    Trend Micro Discovers New Adobe Flash Zero-Day Exploit Used in Malvertisements

    Source:

    http://blog.trendmicro.com/trendlab...ash-zero-day-exploit-used-in-malvertisements/
     
  6. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,009
  7. 142395

    142395 Guest

    Thanks for heads up.
    2 zero day within quite short period!:eek:
    I feel now Adobe is as if Oracle in several years ago...
     
  8. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,009
  9. 142395

    142395 Guest

  10. deBoetie

    deBoetie Registered Member

    Joined:
    Aug 7, 2013
    Posts:
    1,832
    Location:
    UK
    Feeling smug for having banished Flash from anything that matters to me some while back, anything with access to anything at all. VMs reverting to snapshots are your friend.... No Acrobat either.

    It would be interesting to know if Sandboxie trapped this one, I would assume it would, and it would be nice to get confirmation.
     
  11. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    Is there a way to deactivate Flash in IE11?

    This one sounds especially bad.

    Thanks to all for notifying the Forum.
     
    Last edited: Feb 3, 2015
  12. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,009
    Last edited by a moderator: Feb 3, 2015
  13. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
  14. Rmus

    Rmus Exploit Analyst

    Joined:
    Mar 16, 2005
    Posts:
    4,020
    Location:
    California
    Note that the site compromised by the malvertisement does not host the malware; rather, it serves as a redirection trigger:
    Here is a nice description of how these exploits work:

    https://blog.malwarebytes.org/malve...rk-abused-once-again-in-malvertising-attacks/

    This means that if you control your plug-ins per site, if you happen to be bounced around in a redirection exploit, the final site that hosts the malware is not likely to be on your trusted list!

    Adobe has a test site where you can verify that a Flash object will not load with Flash not enabled for that site:

    https://www.adobe.com/software/flash/about/

    flash-test.jpg

    Note also that Javascript, which can be controlled, is used to load the Flash (.swf) object:

    The Adobe page:

    Code:
    script type="text/javascript"
    var props = new Object();
    props.swf = "/swf/software/flash/about/mini_FMA_about_01.swf" 
    Espn.com page:
    Code:
    script type="text/javascript"
    
    swfobject.embedSWF 
    ----
    rich
     
  15. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    Trend Micro has confirmed that the exploit cannot escape Chrome's sandbox and the payload is unable to affect the system. We already knew that Chrome was safe from this exploit, but this shows that it is the sandbox of Chrome which is saving Chrome users from this. If there was currently a Chrome sandbox bypass then Chrome would be at risk too.

    http://blog.trendmicro.com/trendlab...ash-zero-day-exploit-used-in-malvertisements/
    - in comment section

    And more detail on this exploit: http://blog.trendmicro.com/trendlab...k-at-the-exploit-kit-in-cve-2015-0313-attack/
     
  16. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
    From HanJuan EK fires third Flash Player 0day:
     
  17. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,009
    Blocking?
    =
    My question still remains unanswered .........
    &
    https://www.wilderssecurity.com/threads/malwarebytes-anti-exploit.354641/page-63#post-2450580
     
  18. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.