ZeroHour
Security Affairspublished ()ingested @securityaffairs

Kovter trojan patches Flash Player, IE to stop other infections

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2013-2551
Use-After-Free RCE in Microsoft Internet Explorer

CVE-2013-2551 is a use-after-free memory corruption flaw (CWE-416) in Microsoft Internet Explorer. An attacker triggers it by luring a user to a crafted website that causes the browser to access an object that has already been deleted from memory. Successful exploitation allows the attacker to execute arbitrary code on the victim machine, typically in the context of the logged-in user. All Internet Explorer deployments are potentially affected; the source data does not specify version ranges, but the flaw is best known as a long-lived legacy-browser issue exploited by drive-by exploit kits. The vulnerability is confirmed to be exploited in the wild: it is listed in CISA KEV (added 2022-03-28) with known ransomware use, and EPSS assigns it a 74.1% probability of exploitation in the next 30 days (99th percentile).

Do: Apply Microsoft updates for Internet Explorer per vendor instructions, as required by the CISA KEV listing, prioritizing any Windows systems still using IE or IE-based components. As interim mitigation, restrict browsing to trusted sites and ensure users are not running as administrators for routine web activity. Audit legacy environments for obsolete IE usage and migrate those systems to a supported, actively patched browser where updates are no longer feasible.

74% KEV ransomware
  • Microsoft Internet Explorer
masshundreds of millions of legacy Internet Explorer installations worldwide (IE historically held dominant desktop browser market share; exact current count…
CVE-2014-6332
Remote Code Execution via Array Bounds Flaw in Microsoft Windows OLE Automation

CVE-2014-6332 is a memory-corruption flaw (CWE-119) in OleAut32.dll, the OLE Automation component shipped with Microsoft Windows, in which OLE automation arrays are mishandled, allowing out-of-bounds memory access. A remote attacker triggers it by luring a user to a crafted website whose script (typically executed through Internet Explorer) calls into the vulnerable OLE Automation code, corrupting memory on the victim machine. Successful exploitation yields remote code execution with the privileges of the logged-on user, generally giving the attacker full control of the workstation. Because OleAut32.dll is a core OS component, essentially every Windows client and server in circulation at the time was affected; Microsoft addressed it in the November 2014 security updates (MS14-064). The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), indicating known in-the-wild exploitation, and EPSS assigns a 95% probability of exploitation within 30 days (100th percentile); no public PoC is tracked in the source data.

Do: Apply Microsoft's November 2014 Windows/OLE security updates (MS14-064) across all Windows clients and servers, prioritizing internet-facing systems and workstations used for web browsing, and confirm the patched OleAut32.dll is present via patch-management or vulnerability-scanner checks. Because the flaw is KEV-listed and exploitable in a drive-by web-attack scenario, treat any remaining unpatched Windows host as high risk and isolate legacy systems that cannot be updated.

95% KEV
  • Microsoft Windows (OleAut32.dll / OLE Automation) All versions of Microsoft Windows in support at the time of the November 2014 advisory (per CISA: 'Microsoft Windows'); fixed by the November 2014 security upda
mass≈1 billion+ Windows installations (OleAut32.dll ships with every Windows client and server)
CVE-2015-3113
Heap-Based Buffer Overflow RCE in Adobe Flash Player

CVE-2015-3113 is a heap-based buffer overflow (CWE-119) in Adobe Flash Player that is triggered when Flash processes specially crafted SWF content, for example when a browser, ad, or Flash-embedded application renders an attacker-supplied page or file. A successful exploit allows a remote, unauthenticated attacker to execute arbitrary code in the context of the current user. Anyone still running Adobe Flash Player is affected; the product reached end-of-life on December 31, 2020, and CISA's required action is to disconnect or stop using it if it is still deployed. The flaw was exploited in the wild as a zero-day in targeted attacks in June 2015 (fixed by Adobe's emergency update APSB15-11) and was added to the CISA KEV catalog on April 13, 2022; EPSS currently assigns a 99.9% probability of exploitation within 30 days.

Do: Uninstall Adobe Flash Player from all systems, since it has been end-of-life since December 31, 2020 and CISA's required action is to disconnect or stop using anything that still depends on it. If Flash must remain (e.g., legacy admin consoles or kiosks), ensure it runs at least the June 2015 emergency fix (APSB15-11) and ideally the final pre-EOL build 32.0.0.465, and eliminate any browser-facing Flash surface that renders untrusted SWF content. Audit enterprise environments for embedded Flash runtimes and migrate those applications to HTML5 or other supported runtimes.

100% KEV
  • Adobe Flash Player No specific version range given in the CISA data; historically, all Flash Player versions prior to Adobe's June 2015 emergency security update (APSB15-11)
masstens of millions of legacy desktops worldwide still carried Flash at end-of-life (Flash historically ran on ~90% of desktops); residual active installs…
Full article448 words · extracted from securityaffairs.com · click to collapse

Security researcher discovered a strain of the Kovter trojan that has been updating  Flash Player and Internet Explorer to prevent further infections.

The French security expert Kafeine have discovered a new strain of the Kovter malware noticing that the instance of the malicious code he was analyzing was attempting to download the latest version of the Flash Player.

The Kovter malware is used in Ad fraud campaigns, victims were infected by simply clicking on online advertisements and generate revenue for the websites that host the ads.

Flash Player was recently updated by Adobe in order to fix the critical vulnerability (CVE-2015-3113) that had been exploited by threat actors in targeted attacks. Kafeine reported that another exploit kit, the popular Magnitude, was integrated with the code to exploit the flaw in the Flash Player. Several exploit kits including Angler, Neutrino, RIG and Nuclear Pack have later integrated the exploit code for the same vulnerability.

Kafeine noticed a singular behavior for the new strain of the Kovter malware he tested, the malicious code, in fact, was trying to update Flash Player to the latest version 18.0.0.194. It is likely that threat actors patch the infected machine to prevent additional infections through other threat agents.

“Checking my systems I noticed multiple VM trying to grab last version of Flash and thought they were not properly setup allowing Flash Player to auto-update (which we do not want obviously – we want to keep them exploitable and also avoid behavioural/network noise).” wrote Kafeine in a blog post. “The goal is most probably to close the door of the system to additional infection via DriveBy.”

The Kovter malware does much more, it also updates the Internet Explorer browser to the latest version patching two flaws, the CVE-2013-2551 and CVE-2014-6332, exploited by a number of threat actors.

The behavior is not new, in the past security researchers observed other malicious code patching infected systems to close the door to further infection. Kafeine explained that the Betabot Trojan operates in a similar way to prevent future infections via exploit kits. The expert is surprised by the rapidity into patching the issue on the machine infected by the Kovter.

“An exploit get its way to almost all exploit kits in a matter of days, and owners of a big adfraud botnet decide to fix the issue on their ‘fleet’ almost as fast. I find this fast action/reaction interesting,” said Kafeine.

Kafeine reported that Kovter is also being served by the principal exploit kits in the wild, including the Angler EK, the Nuclear Pack, and Neutrino EK.

[adrotate banner=”9″] [adrotate banner=”12″]

(Security Affairs – Kovter, malware)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/38289/cyber-crime/kovter-patches-flash-player-ie.html