CVE-2016-4171 – Adobe Flash Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-0147 | Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulnerability." Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulnerability." NVD description · AI analysis pending | 8.8 | 16% |
| — | ||
| CVE-2016-1010 | Integer Overflow RCE in Adobe Flash Player and AIR CVE-2016-1010 is an integer overflow (CWE-190) in Adobe Flash Player and Adobe AIR that allows attackers to execute arbitrary code via unspecified vectors, most plausibly by inducing a user to open attacker-supplied Flash content, consistent with the user-interaction requirement in its CVSS 3.1 score of 8.8. It affects Flash Player before 18.0.0.333 (Extended Support Release) and 19.x through 21.x before 21.0.0.182 on Windows and OS X, Flash Player before 11.2.202.577 on Linux, and Adobe AIR, AIR SDK, and AIR SDK & Compiler releases before 21.0.0.176, with Samsung X14J firmware also listed as an affected bundler of the Flash component. Successful exploitation yields arbitrary code execution in the context of the Flash runtime, typically sufficient to install malware or move laterally under the user's privileges. Anyone still running these now end-of-life runtimes, including embedded deployments such as the Samsung X14J firmware, is exposed. CISA added the flaw to the KEV catalog on 2022-05-25, and related reporting ties Windows zero-day Flash exploitation to targeted attacks by the FruityArmor APT, indicating in-the-wild exploitation; EPSS assigns a 19.4% probability of exploitation within 30 days (97th percentile), though no public PoC is known. Do: Upgrade Flash Player to 18.0.0.333 (ESR), 21.0.0.182 (Windows/OS X), or 11.2.202.577 (Linux), and Adobe AIR, AIR SDK, and AIR SDK & Compiler to 21.0.0.176. Since all impacted products are end-of-life, CISA's required action is to disconnect them if still in use; prioritize removing or disabling Flash/AIR entirely and verify that no embedded deployments (e.g., Samsung X14J firmware) still rely on Flash. Hunt for signs of targeted exploitation consistent with FruityArmor APT activity, such as unexpected Flash content and suspicious child processes spawned from browsers or Flash-enabled applications. | 8.8 | 19% | KEV |
| masson the order of hundreds of millions of desktop installations at the time of disclosure (Flash was near-universal on PCs); a far smaller, shrinking legacy base… | |
| CVE-2016-4117 | Arbitrary Code Execution in Adobe Flash Player 21.0.0.226 and earlier CVE-2016-4117 is a critical (CVSS 3.1: 9.8) arbitrary code execution vulnerability in Adobe Flash Player 21.0.0.226 and earlier, in which unspecified vectors in the Flash runtime allow remote attackers to execute arbitrary code. It is triggered by delivering malicious Flash content over a network — for example a crafted SWF loaded by a browser or an application that embeds Flash — and, per its CVSS scoring, requires no privileges or authentication. A successful exploit gives the attacker code execution in the context of the Flash runtime (typically the user's browser process), which public reporting shows was used to deliver espionage tooling and, per CISA, is also known to be used in ransomware campaigns. Anyone running Flash Player 21.0.0.226 or earlier was affected, including users of the flash-player packages shipped for Red Hat Enterprise Linux Desktop, Server (including the RHUI variant) and Workstation, openSUSE, openSUSE Evergreen, and SUSE Linux Enterprise Desktop and the SUSE Linux Enterprise Workstation Extension. The bug was exploited in the wild in May 2016 — related headlines tie it to the BlackOasis APT 'Operation Daybreak' espionage campaign using FinFisher — and it was added to the CISA KEV on 2022-03-03 with known ransomware use and a very high 94.4% EPSS. Do: Per CISA's required action, Flash Player is end-of-life: remove or disable Flash wherever it is still present and uninstall the flash-player packages on any remaining RHEL, SUSE or openSUSE hosts, especially internet-facing systems. If a legacy system must keep Flash, ensure it runs a release later than 21.0.0.226 (a fixed build from the May 2016 Adobe update or later) and restrict it from untrusted web content. | 9.8 | 94% | KEV ransomware PoC |
| mass≈100M+ desktop users at the time of disclosure (Flash was then near-universal); residual small base of end-of-life installs today | |
| CVE-2016-4171 | Unspecified Remote Code Execution Flaw in Adobe Flash Player CVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player that allows remote code execution; neither the CVE description nor CISA provides technical detail on the underlying flaw. As a Flash RCE, it is presumably triggered by getting a victim to load attacker-supplied Flash content (for example a malicious SWF in a web page or document), though the available data does not confirm the attack vector. Successful exploitation would let an attacker execute arbitrary code with the privileges of the user running Flash, typically yielding a foothold on the endpoint. All Adobe Flash Player deployments are affected per the data, and because Flash reached end-of-life at the end of 2020, anyone still running it is on an unpatched legacy product. The vulnerability is known exploited: CISA added it to the KEV catalog on 2022-03-25 (ransomware use unknown), EPSS assigns a 20.2% probability of exploitation within 30 days (97th percentile), and no public proof-of-concept is known. Do: Per CISA's required action, remove or disconnect Adobe Flash Player wherever it is still in use - the product is end-of-life and unpatched, so there is no fixed version to upgrade to. Audit endpoints and internal applications for Flash dependencies (standalone Flash, projector files, legacy intranet apps), migrate or retire them, and as a stopgap block SWF/Flash content at mail and web gateways. | 9.8 | 20% | KEV |
| massplausibly millions of residual Flash installs worldwide, though the number actively exposed today is unknown (Flash was historically on nearly every PC but is… |
Full article407 words · extracted from securelist.com · click to collapse
Earlier today, Adobe published the security advisory APSA16-03, which describes a critical vulnerability in Adobe Flash Player version 21.0.0.242 and earlier versions for Windows, Macintosh, Linux, and Chrome OS:
A few of months ago, we deployed a new set of technologies into our products designed to identify and block zero day attacks. These technologies already proved its effectiveness earlier this year, when they caught an Adobe Flash zero day exploit, CVE-2016-1010. Earlier this month, we caught another zero-day Adobe Flash Player exploit deployed in targeted attacks.
We believe these attacks are launched by an APT Group we call “ScarCruft”.
ScarCruft is a relatively new APT group; victims have been observed in several countries, including Russia, Nepal, South Korea, China, India, Kuwait and Romania. The group has several ongoing operations utilizing multiple exploits — two for Adobe Flash and one for Microsoft Internet Explorer.
Currently, the group is engaged in two major operations: Operation Daybreak and Operation Erebus. The first of them, Operation Daybreak, appears to have been launched by ScarCruft in March 2016 and employs a previously unknown (0-day) Adobe Flash Player exploit, focusing on high profile victims. The other one, “Operation Erebus” employs an older exploit, for CVE-2016-4117 and leverages watering holes. It is also possible that the group deployed another zero day exploit, CVE-2016-0147, which was patched in April.
We will publish more details about the attack once Adobe patches the vulnerability, which should be on June 16. Until then, we confirm that Microsoft EMET is effective at mitigating the attacks. Additionally, our products detect and block the exploit, as well as the malware used by the ScarCruft APT threat actor.
* More information about the ScarCruft APT and Operation Daybreak is available to customers of Kaspersky Intelligence Services. Contact: [email protected]
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/cve-2016-4171-adobe-flash-zero-day-used-in-targeted-attacks/75082/