ZeroHour
Security Affairspublished ()ingested @securityaffairs

Adobe patches multiple flaws including a Flash Zero

criticalVulnerability exploited in the wildimportance 60CVE-2016-7892

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-7892
Use-After-Free RCE in Adobe Flash Player TextField (CVE-2016-7892)

CVE-2016-7892 is a use-after-free memory-corruption flaw (CWE-416) in the TextField class of Adobe Flash Player. An attacker triggers it by convincing a user to open malicious Flash (SWF) content, typically embedded in a web page or delivered document; the CVSS vector (AV:N/AC:L/PR:N/UI:R) confirms exploitation requires network access and user interaction but no privileges. Successful exploitation yields arbitrary code execution with the victim user's privileges (CVSS 3.1: 8.8 High). Anyone running affected Flash versions is affected — Adobe Flash Player Desktop Runtime 23.0.0.207 and earlier, and the 11.2.202.644-and-earlier Linux line — with the practical risk concentrated on any systems still executing Flash content today. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), indicating known in-the-wild exploitation; no public proof-of-concept is known, ransomware use is unknown, and EPSS is 18.8% (97th percentile).

Do: Update Flash Player to a version later than 23.0.0.207 (desktop) or 11.2.202.644 (Linux) via the December 2016 Adobe security update — or, preferably, since Flash is end-of-life per CISA, uninstall or disable Flash and stop rendering SWF content entirely. Inventory any systems still invoking Flash (legacy browser plugins, embedded or enterprise applications that render Flash content) and retire or disconnect them, as CISA's required action directs. Because exploitation requires user interaction, blocking untrusted Flash content and email-delivered SWF files further reduces risk.

8.819% KEV
  • Adobe Flash Player Desktop Runtime 23.0.0.207 and earlier
  • Adobe Flash Player (Linux 11.2.x extended support line) 11.2.202.644 and earlier
mass≈1 billion+ installs at disclosure (Flash ran on roughly 99% of internet-connected PCs in 2016); current active footprint unknown and much smaller post-EOL
Full article300 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 13, 2016

Adobe issued security patches that address multiple flaws in 9 products, including fixes for zero-day vulnerabilities that has been exploited in the wild.

Adobe has issued security updates to fix vulnerabilities in nine products, including patches for zero-day flaws that has been exploited in targeted attacks.

The version 24.0.0.186 of Flash Player addresses 17 vulnerabilities, some of them can be exploited by attackers for arbitrary code execution. The most severe vulnerability fixed by the updates is a use-after-free issue, tracked as is CVE-2016-7892, that was reported to Adobe by an individual who wanted to remain anonymous.

The remaining flaws in the Adobe Flash Player vulnerabilities were reported to the company by independent researchers and experts from multiple organizations, Pangu LAB, Tencent, Microsoft, CloverSec Labs, Qihoo 360, Trend Micro’s Zero Day Initiative (ZDI) and Palo Alto Networks.

“Adobe has released security updates for Adobe Flash Player for Windows, Macintosh, Linux and Chrome OS.  These updates address critical vulnerabilities that could potentially allow an attacker to take control of the affected system.” reads the Adobe Security Bulletin.

“Adobe is aware of a report that an exploit for CVE-2016-7892 exists in the wild, and is being used in limited, targeted attacks against users running Internet Explorer (32-bit) on Windows.”

Adobe confirmed the existence in the wild of an exploit code for the CVE-2016-7892 vulnerability, the company also revealed that it was used in limited, targeted attacks against Windows users running a 32-bit version of Internet Explorer.

Adobe also issued other security updates that patch vulnerabilities in other products, including Animate, Experience Manager Forms, DNG Converter, InDesign, ColdFusion Builder, Digital Editions, and RoboHelp.

None of the above vulnerabilities had been exploited in the wild.

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – Adobe Flash , Zero-Day, hacking)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/54361/hacking/adobe-flash-player-zero-day.html