ZeroHour
Security Affairspublished ()ingested @securityaffairs

New campaign leverages RIG Exploit kit to deliver the Cerber Ransomware

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2015-5122
Use-After-Free RCE in Adobe Flash Player AS3 DisplayObject

CVE-2015-5122 is a use-after-free vulnerability (CWE-416) in the DisplayObject class of the ActionScript 3 implementation in Adobe Flash Player. It is triggered when the Flash runtime processes crafted AS3/SWF content, typically a malicious Flash file loaded from a web page or delivered via an exploit kit, causing freed memory to be reused and letting a remote attacker execute arbitrary code in the user's context or crash the player (denial of service). Any system or browser still running affected Flash Player builds is affected; because Flash has reached end-of-life and no longer receives updates, environments that still rely on it are the primary at-risk population. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-04-13, related reporting shows it used by exploit kits and in watering-hole attacks, and EPSS assigns a 93.7% probability of exploitation within 30 days.

Do: Follow CISA's required action: uninstall or disconnect Adobe Flash Player wherever it is still in use, since the product is end-of-life and receives no further patches. Inventory browsers, legacy web applications, and bundled software for residual Flash plug-ins and SWF content, and disable Flash content loading where immediate removal is not possible. For systems that must keep running Flash, isolate them and block exposure to untrusted web content, as drive-by exploit kit delivery was the observed attack pattern.

94% KEV
  • Adobe Flash Player
mass~1 billion+ historical installs (Flash ran on most internet-connected PCs at the 2015 disclosure); current residual post-EOL base unknown
CVE-2015-8651
Integer Overflow in Adobe Flash Player Enables Remote Code Execution

CVE-2015-8651 is an integer overflow (CWE-189, a numeric error-handling flaw) in Adobe Flash Player that allows attackers to execute arbitrary code when Flash processes specially crafted content. The realistic trigger is a drive-by web attack: a user browses to a compromised or attacker-controlled page, often reached through malvertising or exploit kits, and the malicious Flash (SWF) content exploits the overflow in the user's browser or standalone player. Successful exploitation gives the attacker code execution in the context of the logged-in user, typically as a delivery mechanism for ransomware, information stealers, or miners, as seen in exploit-kit campaigns of the era (RIG, Neptune, Stegano, and others were distributing Flash exploits at the time). Anyone running an affected version of Adobe Flash Player was exposed; Flash was near-universally deployed in 2015-2016, though the product has since reached end of life (December 31, 2020) and modern browsers no longer load it. Exploitation is confirmed in the wild: CISA added this CVE to its Known Exploited Vulnerabilities catalog on 2022-05-25, EPSS assigns it a 67.9% probability of exploitation in the next 30 days (99th percentile), and no public PoC is cataloged.

Do: Uninstall or disable Adobe Flash Player on all remaining systems, since it is end-of-life and CISA's required action is to disconnect/remove it if still in use. If legacy Flash cannot be removed immediately, apply Adobe's January 2016 security update (APSB16-01) and restrict those hosts from untrusted web browsing and ad content. Inventory for standalone Flash players, intranet applications that embed SWF content, and copies of Flash bundled inside other applications.

68% KEV
  • Adobe Flash Player
mass~1 billion+ installations historically (near-universal desktop Flash deployment in 2015-2016); residual exposure today limited to unmigrated legacy systems,…
CVE-2016-0034
Remote Code Execution via Crafted Website in Microsoft Silverlight 5

CVE-2016-0034 is a memory-corruption flaw in the Microsoft Silverlight 5 runtime, which mishandles negative offsets during decoding, corrupting object headers. An attacker triggers it by convincing a user to visit a crafted website while the vulnerable Silverlight plug-in is active in their browser, requiring no privileges but user interaction. Successful exploitation allows the attacker to execute arbitrary code in the context of the logged-in user (or crash the browser/application). Anyone running Microsoft Silverlight 5 versions before 5.1.41212.0 is affected; Silverlight is now end-of-life, so remaining installations are legacy deployments. The flaw was exploited in the wild through exploit kits such as Angler and RIG to deliver ransomware like Cerber, and it was added to the CISA KEV catalog in May 2022 with known ransomware use.

Do: Upgrade Silverlight to version 5.1.41212.0 (January 2016 security update) on any system where it remains installed. Because Silverlight is end-of-life, CISA's KEV required action is to disconnect or remove it and migrate any legacy Silverlight-based web applications; prioritize internet-facing endpoints and users of Internet Explorer/legacy browsers, where the plug-in can still be invoked.

8.870% KEV ransomware
  • microsoft Silverlight Silverlight 5 before 5.1.41212.0 (fixed in 5.1.41212.0, January 2016 Patch Tuesday)
masshistorically hundreds of millions of installs (Silverlight reached roughly 70% of consumer devices at peak); residual active installs today likely number in…
CVE-2016-1019
Arbitrary code execution flaw in Adobe Flash Player, used in ransomware attacks

CVE-2016-1019 is a remotely exploitable flaw in Adobe Flash Player that lets an attacker cause a denial of service or, in the worst case, execute arbitrary code on the victim's system. It is triggered remotely, typically when a user views malicious Flash content delivered through a web browser, an application, or a document that embeds Flash content. A successful attack runs code with the privileges of the logged-on user, making the bug a useful foothold for deploying malware, including ransomware. Anyone still running Adobe Flash Player is potentially affected - the product is end-of-life (support ended December 31, 2020), but it persists on legacy desktops, intranet applications, kiosks, and embedded or industrial systems; the CISA data does not list specific affected version ranges. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on March 3, 2022, notes known ransomware use, and EPSS assigns a 22.5% probability of exploitation in the next 30 days (98th percentile), though no public proof-of-concept is catalogued.

Do: Per CISA's required action, disconnect or remove any system still running Adobe Flash Player, since the product is end-of-life and receives no further security updates; the bug was patched in Adobe's 2016 updates, so only long-unupdated or embedded Flash installs remain vulnerable. Uninstall Flash from browsers and legacy software and confirm that no internal applications or sites still serve or require SWF content. Because exploitation is tied to ransomware campaigns, prioritize user workstations and any internet-facing host with Flash installed.

9.822% KEV ransomware
  • Adobe Flash Player
mass≈ millions of legacy endpoints worldwide (Flash historically ran on ~99% of internet-connected PCs; current residual install count unknown)
CVE-2016-3298
Information Disclosure in Microsoft Internet Explorer Messaging API

CVE-2016-3298 is an information disclosure flaw (CWE-200) in the Microsoft Internet Messaging API used by Internet Explorer, in which the API improperly handles objects in memory. Exploitation requires driving Internet Explorer to process attacker-influenced content so the Messaging API mishandles memory, after which the attacker can probe whether specific files exist on the victim's disk. An attacker gains only limited reconnaissance value — confirming file presence for fingerprinting — rather than code execution or direct data theft. Only systems running Microsoft Internet Explorer, as cataloged by CISA, are affected; CISA added the bug to the Known Exploited Vulnerabilities catalog on 2022-05-24, confirming exploitation in the wild, though any ransomware association is unknown. EPSS estimates a 32.8% probability of exploitation within 30 days (98th percentile), no public proof-of-concept is known, and a CVSS score has not yet been published in this dataset.

Do: Apply Microsoft's security update for CVE-2016-3298 per vendor instructions, as mandated by the CISA KEV catalog (added 2022-05-24, so remediation deadlines apply to federal agencies and many regulated environments). Audit any Windows hosts where Internet Explorer is still used for interactive browsing and confirm the patch is installed; because the flaw only permits probing for file existence, residual risk after patching is low.

6.533% KEV
  • Microsoft Internet Explorer
masshundreds of millions of Windows devices (Internet Explorer shipped as a built-in Windows component for decades)
CVE-2016-4117
Arbitrary Code Execution in Adobe Flash Player 21.0.0.226 and earlier

CVE-2016-4117 is a critical (CVSS 3.1: 9.8) arbitrary code execution vulnerability in Adobe Flash Player 21.0.0.226 and earlier, in which unspecified vectors in the Flash runtime allow remote attackers to execute arbitrary code. It is triggered by delivering malicious Flash content over a network — for example a crafted SWF loaded by a browser or an application that embeds Flash — and, per its CVSS scoring, requires no privileges or authentication. A successful exploit gives the attacker code execution in the context of the Flash runtime (typically the user's browser process), which public reporting shows was used to deliver espionage tooling and, per CISA, is also known to be used in ransomware campaigns. Anyone running Flash Player 21.0.0.226 or earlier was affected, including users of the flash-player packages shipped for Red Hat Enterprise Linux Desktop, Server (including the RHUI variant) and Workstation, openSUSE, openSUSE Evergreen, and SUSE Linux Enterprise Desktop and the SUSE Linux Enterprise Workstation Extension. The bug was exploited in the wild in May 2016 — related headlines tie it to the BlackOasis APT 'Operation Daybreak' espionage campaign using FinFisher — and it was added to the CISA KEV on 2022-03-03 with known ransomware use and a very high 94.4% EPSS.

Do: Per CISA's required action, Flash Player is end-of-life: remove or disable Flash wherever it is still present and uninstall the flash-player packages on any remaining RHEL, SUSE or openSUSE hosts, especially internet-facing systems. If a legacy system must keep Flash, ensure it runs a release later than 21.0.0.226 (a fixed build from the May 2016 Adobe update or later) and restrict it from untrusted web content.

9.894% KEV ransomware PoC
  • adobe Flash Player 21.0.0.226 and earlier (all editions)
  • redhat Enterprise Linux Desktop (flash-player package)
  • redhat Enterprise Linux Server (flash-player package)
  • +6 more
mass≈100M+ desktop users at the time of disclosure (Flash was then near-universal); residual small base of end-of-life installs today
CVE-2016-7200
+1 in the same advisory: …7201
Memory Corruption RCE in Microsoft Edge Chakra JavaScript Engine (CVE-2016-7200)

CVE-2016-7200 is an out-of-bounds write (CWE-787) causing memory corruption in the Chakra JavaScript scripting engine used by Microsoft Edge. A remote attacker triggers it by luring a user to a crafted website, where malicious JavaScript processed by Chakra corrupts memory (the CVSS user-interaction requirement confirms browsing is the attack vector). Successful exploitation allows arbitrary code execution in the context of the logged-on user, or denial of service; confidentiality, integrity, and availability are all rated high. All users of the legacy (Chakra-based) Microsoft Edge browser at the time of the November 2016 disclosure were affected. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2022-03-28), public proof-of-concept exploits exist, and it was added to the RIG and Sundown exploit kits, including campaigns delivering Cerber ransomware.

Do: Apply the vendor's cumulative security updates for Microsoft Edge via Windows Update, per CISA's required action, and verify that all Windows 10 endpoints have post-November-2016 Edge updates installed. Note that the current Chromium-based Edge does not use the Chakra engine, so upgrading to a supported Edge/OS build eliminates the vulnerable component. Until patched, limit exposure by steering users away from untrusted websites, since drive-by exploit kits (RIG, Sundown) were actively weaponizing this flaw.

8.882% KEV PoC ×3
  • microsoft edge
masstens to hundreds of millions of Edge users at the time of disclosure (Edge was the default browser on Windows 10)
Full article413 words · extracted from securityaffairs.com · click to collapse

Experts from Heimdal Security warned of a spike in cyber attacks leveraging the popular RIG Exploit kit to deliver the Cerber Ransomware.

The RIG exploit kit is even more popular in the criminal ecosystem, a few days ago security experts at Heimdal Security warned of a spike in cyber attacks leveraging the popular Neutrino and RIG EKs.

Now security experts from Heimdal Security are warning of a new campaign leveraging the RIG exploit kit that targets outdated versions of popular applications to distribute the Cerber ransomware.

The attackers leverage an array of malicious domains to launch drive-by attacks against visitors trying to exploit flaws in outdated versions of popular applications such as Flash, Internet Explorer, or Microsoft Edge.

“At the moment, cybercriminals are using a swarm of malicious domains to launch drive-by attacks against unsuspecting users.” states the analysis published by Heimdal Security.

“The campaign works by injecting malicious scripts into insecure or compromised systems. Victims can get infected simply by browsing the compromised or infected websites, without clicking on anything. What exposes them to this attack are outdated versions of the following apps: Flash Player, Silverlight, Internet Explorer or Edge.”

The crooks compromise websites to inject malicious scripts that allow exploiting the flaws in the victim’s browser even without user interaction.  reports.

RIG Exploit kit

This new campaign leverages on a RIG exploit kit that attempts to exploit the following 8 vulnerabilities:

According to the experts from Heimdal security, this variant of the RIG exploit is the Empire Pack version (RIG-E). Cyber criminals also abused domains that are part of the so-called Pseudo-Darkleech gateway that was also exploited by cyber gangs in June 2016 to deliver the CryptXXX ransomware in several campaigns leveraging on the Neutrino Exploit Kit.

It is important to highlight that the success of campaigns like this one is determined by the failure in applying security updates in popular software.

“As you can see, cybercriminals often use vulnerabilities already patched by the software developer in their attacks, because they know that most users fail to apply updates when they’re released. In spite of the wave of attacks, many Internet users still choose to ignore updates, but we hope that alerts such as this one will change their mind and make them more aware of the key security layer that updates represent.” states the report.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – RIG Exploit Kit, cybercrime)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/55354/cyber-crime/rig-exploit-kit-cerber.html