Unpatched Vulnerability (0day) in Flash Player is being exploited by Angler EK

Discussion in 'other security issues & news' started by FleischmannTV, Jan 21, 2015.

  1. Compu KTed

    Compu KTed Registered Member

    I think Adobe should rename their flash -player to PATCH-PLAYER :)
     
  2. anon

    anon Registered Member

  3. anon

    anon Registered Member

  4. itman

    itman Registered Member

    I think SIEVE-PLAYER is more appropriate. They never will be able to patch all the holes in it.
     
  5. FleischmannTV

    FleischmannTV Registered Member

    Trend Micro Discovers New Adobe Flash Zero-Day Exploit Used in Malvertisements

    Source:

    http://blog.trendmicro.com/trendlab...ash-zero-day-exploit-used-in-malvertisements/
     
  6. anon

    anon Registered Member

  7. 142395

    142395 Guest

    Thanks for heads up.
    2 zero day within quite short period!:eek:
    I feel now Adobe is as if Oracle in several years ago...
     
  8. anon

    anon Registered Member

  9. 142395

    142395 Guest

  10. deBoetie

    deBoetie Registered Member

    Feeling smug for having banished Flash from anything that matters to me some while back, anything with access to anything at all. VMs reverting to snapshots are your friend.... No Acrobat either.

    It would be interesting to know if Sandboxie trapped this one, I would assume it would, and it would be nice to get confirmation.
     
  11. hawki

    hawki Registered Member

    Is there a way to deactivate Flash in IE11?

    This one sounds especially bad.

    Thanks to all for notifying the Forum.
     
    Last edited: Feb 3, 2015
  12. anon

    anon Registered Member

    Last edited by a moderator: Feb 3, 2015
  13. xxJackxx

    xxJackxx Registered Member

  14. Rmus

    Rmus Exploit Analyst

    Note that the site compromised by the malvertisement does not host the malware; rather, it serves as a redirection trigger:
    Here is a nice description of how these exploits work:

    https://blog.malwarebytes.org/malve...rk-abused-once-again-in-malvertising-attacks/

    This means that if you control your plug-ins per site, if you happen to be bounced around in a redirection exploit, the final site that hosts the malware is not likely to be on your trusted list!

    Adobe has a test site where you can verify that a Flash object will not load with Flash not enabled for that site:

    https://www.adobe.com/software/flash/about/

    flash-test.jpg

    Note also that Javascript, which can be controlled, is used to load the Flash (.swf) object:

    The Adobe page:

    Code:
    script type="text/javascript"
    var props = new Object();
    props.swf = "/swf/software/flash/about/mini_FMA_about_01.swf" 
    Espn.com page:
    Code:
    script type="text/javascript"
    
    swfobject.embedSWF 
    ----
    rich
     
  15. WildByDesign

    WildByDesign Registered Member

    Trend Micro has confirmed that the exploit cannot escape Chrome's sandbox and the payload is unable to affect the system. We already knew that Chrome was safe from this exploit, but this shows that it is the sandbox of Chrome which is saving Chrome users from this. If there was currently a Chrome sandbox bypass then Chrome would be at risk too.

    http://blog.trendmicro.com/trendlab...ash-zero-day-exploit-used-in-malvertisements/
    - in comment section

    And more detail on this exploit: http://blog.trendmicro.com/trendlab...k-at-the-exploit-kit-in-cve-2015-0313-attack/
     
  16. MrBrian

    MrBrian Registered Member

    From HanJuan EK fires third Flash Player 0day:
     
  17. anon

    anon Registered Member

    Blocking?
    =
    My question still remains unanswered .........
    &
    https://www.wilderssecurity.com/threads/malwarebytes-anti-exploit.354641/page-63#post-2450580
     
  18. FleischmannTV

    FleischmannTV Registered Member

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice