ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Adobe Fix for CVE-2011

criticalExploit / PoCimportance 60CVE-2011-0609

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2011-0609
Unspecified Remote Code Execution Vulnerability in Adobe Flash Player

Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute arbitrary code or cause a denial-of-service condition. The flaw is triggered remotely, almost certainly via malicious Flash content processed by the player in a browser or standalone runtime, although Adobe did not disclose detailed technical specifics for this CVE. Successful exploitation gives an attacker the ability to run code with the privileges of the user running Flash, or to crash the application. Anyone running affected builds of Flash Player is exposed; at the time of disclosure in 2011 that meant nearly every internet-connected desktop, whereas today it is limited to residual end-of-life installs. The vulnerability is listed in the CISA KEV catalog (added 2022-06-08) and carries a high EPSS score of 66.8% (99th percentile), indicating known exploitation in the wild, though no public proof-of-concept is known.

Do: Flash Player is end-of-life and no longer receives security updates, so inventory systems for any remaining Flash installs and remove or disable them where possible; CISA's required action is to disconnect impacted products if still in use. For legacy systems that must retain Flash, isolate them from untrusted web content and treat this code execution flaw as actively exploited.

67% KEV
  • Adobe Flash Player
masson the order of hundreds of millions of installs at the time of disclosure (Flash ran on ~99% of internet-connected PCs in 2011); the number of residual…
Full article449 words · extracted from securelist.com · click to collapse

Incidents

Incidents

22 Mar 2011

minute read

Adobe released its fix for CVE-2011-0609 this afternoon, making good on last week’s advisory dealing with the latest Flash zero-day. Kaspersky Lab products detected the variants as “Trojan-Dropper.MSExcel.SWFDrop” this past week.

While we questioned the usefulness of Flash functionality within Excel spreadsheet cells last week, attackers were sending out emails containing just these sorts of files. Our Kaspersky Security Network statistics saw very low numbers spread out across the globe, revealing attackers making targeted use of this zero-day attack.

While there were few attacks seen using this unusual mix of a Microsoft Office and Flash implementation, a question remains, why do Adobe patches continue to take so long to roll out at this point?

On one hand, we saw Google Chrome’s update for the same flash vulnerability roll out almost immediately last Tuesday, in part because of Chrome’s close integration with Flash. The Chrome dev team brags security – it’s in their browser design and security is a major part of their process. Chrome security updates are clean, easy and quick.

On the other hand, the rest of the world using Flash (which is almost 99% of internet connected PC’s, according to Adobe) was browsing with vulnerable software and provided some complicated options as attackers set their crosshairs on their next high-value target. At the same time, Flash is one of the most vulnerable applications on the web, meaning users have not been updating their software – its many versions of updates aren’t necessarily clean, easy or quick.

Adobe’s sandbox was a step in the right direction for Reader X. But attackers are responding with improvements in their own offenses. A sandbox delays exploitation, it doesn’t end exploitation – this month, Stephen Fewer
won pwn2own with an attack chaining 3 exploits together to pop out of Internet Explorer’s sandbox and compromise a Windows 7 system also protected by DEP/ASLR. In the meantime, we welcome more improvements and speed to this inevitable patching process. And please update your Adobe Reader, Flash, and Acrobat software to the latest versions.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/adobe-fix-for-cve-2011-0609/29772/