ZeroHour
Cisco Talospublished ()ingested

News Flash! Another Adobe Flash Zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2016-1019

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-1019
Arbitrary code execution flaw in Adobe Flash Player, used in ransomware attacks

CVE-2016-1019 is a remotely exploitable flaw in Adobe Flash Player that lets an attacker cause a denial of service or, in the worst case, execute arbitrary code on the victim's system. It is triggered remotely, typically when a user views malicious Flash content delivered through a web browser, an application, or a document that embeds Flash content. A successful attack runs code with the privileges of the logged-on user, making the bug a useful foothold for deploying malware, including ransomware. Anyone still running Adobe Flash Player is potentially affected - the product is end-of-life (support ended December 31, 2020), but it persists on legacy desktops, intranet applications, kiosks, and embedded or industrial systems; the CISA data does not list specific affected version ranges. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on March 3, 2022, notes known ransomware use, and EPSS assigns a 22.5% probability of exploitation in the next 30 days (98th percentile), though no public proof-of-concept is catalogued.

Do: Per CISA's required action, disconnect or remove any system still running Adobe Flash Player, since the product is end-of-life and receives no further security updates; the bug was patched in Adobe's 2016 updates, so only long-unupdated or embedded Flash installs remain vulnerable. Uninstall Flash from browsers and legacy software and confirm that no internal applications or sites still serve or require SWF content. Because exploitation is tied to ransomware campaigns, prioritize user workstations and any internet-facing host with Flash installed.

9.822% KEV ransomware
  • Adobe Flash Player
mass≈ millions of legacy endpoints worldwide (Flash historically ran on ~99% of internet-connected PCs; current residual install count unknown)

Indicators of compromiseAll →

TypeIndicatorContext
ipv421.0.0.182er ESR. Per Adobe's advisory , the mitigation introduced in 21.0.0.182 is not present in the ESR 18.0 branch. For users who do not
ipv421.0.0.197curity advisory published on April 5, Flash Player versions 21.0.0.197 and earlier are susceptible to compromise via CVE-2016-1019
Full article327 words · extracted from blog.talosintelligence.com · click to collapse

Thursday, April 7, 2016 16:24

In today's threat landscape, Adobe Flash Player unfortunately remains an attractive attack vector for adversaries to exploit and compromise systems. Over the past year, Talos has observed several instances where adversaries have identified zero-day vulnerabilities and exploited them to compromise systems. Talos is aware of reports that CVE-2016-1019, an Adobe Flash 0-day vulnerability, is currently being exploited in the wild and is affecting systems running Windows 10 and earlier.

According to the Adobe Flash Player security advisory published on April 5, Flash Player versions 21.0.0.197 and earlier are susceptible to compromise via CVE-2016-1019. This includes Flash Player version 20.0.0.306 as well as Flash Player Extended Support Release (ESR) version 18.0.0.333 and earlier. One special note is that as of March 10, 2016, Adobe introduced a mitigation that prevents exploitation of CVE-2016-1019 in Flash version 21.0.0.182 and later.

Due to the continued nature of adversaries exploiting Adobe Flash, Talos is advising everyone to take precautions to mitigate the impact of this vulnerability and disable or remove unnecessary browser plugins. If this is not possible, Talos recommends all users upgrade Flash on their computers immediately. This is especially important for organizations who currently use Flash Player ESR. Per Adobe's advisory, the mitigation introduced in 21.0.0.182 is not present in the ESR 18.0 branch. For users who do not have the ability to update or remove Flash, Talos recommends that you make Adobe Flash "click-to-play" in your browser or to use a browser that sandboxes Flash effectively.

Talos is releasing the following Snort rules in response to this zero-day vulnerability. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. For the most current rule information, please refer to your FireSIGHT Management Center or Snort.org.

Snort Rules: 38429-38434


AMP is automatically covering the use of this Flash exploit in the wild as observed in the Nuclear and Magnitude exploit kits.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/adobe-0-day/