ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Adobe Issues Patch for Actively Exploited Flash Player Zero

criticalVulnerability exploited in the wildimportance 60CVE-2018-5002CVE-2018-5000CVE-2018-5001

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-5000
+1 in the same advisory: …5001
Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability.

Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could lead to information disclosure.

NVD description · AI analysis pending
6.514%
  • adobe flash player desktop runtime
  • adobe flash player
  • adobe enterprise linux desktop
  • +1 more
CVE-2018-5002
Stack Buffer Overflow RCE in Adobe Flash Player

CVE-2018-5002 is a stack-based buffer overflow (out-of-bounds write) in Adobe Flash Player that can lead to remote code execution. It is triggered when the affected Flash Player processes malicious Flash content, typically delivered remotely through a browser or another application that renders SWF content. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Flash Player. Anyone still running affected versions of Adobe Flash Player is affected, though the product is now end-of-life, and CISA's required action is to disconnect or remove it if still in use. The flaw is being exploited in the wild per its inclusion in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), with a 25.4% EPSS probability of exploitation within 30 days (98th percentile); no public PoC is known.

Do: Because Flash Player is end-of-life, the recommended action is to fully uninstall Adobe Flash Player from all systems, prioritizing internet-facing and server workstations, and block or disable Flash content in browsers. Where Flash cannot yet be removed, ensure the latest available Flash release with the 2018 vendor fix for this issue is installed and restrict rendering of untrusted SWF content. Hunt for signs of exploitation per the KEV entry, and treat any remaining Flash-enabled endpoint as a legacy-asset risk.

7.825% KEV
  • Adobe Flash Player All versions released prior to the vendor's 2018 security update addressing this flaw; the product is now end-of-life (no patched release line is maintained)
mass≈ tens of millions of legacy installations worldwide (Flash Player historically shipped on nearly every Windows PC and in major browsers)
Full article372 words · extracted from thehackernews.com · click to collapse

The Hacker NewsJun 07, 2018

If you have already uninstalled Flash player, well done! But if you haven't, here's another great reason for ditching it.

Adobe has released a security patch update for a critical vulnerability in its Flash Player software that is actively being exploited in the wild by hackers in targeted attacks against Windows users.

Independently discovered last week by several security firms—including ICEBRG, Qihoo 360 and Tencent—the Adobe Flash player zero-day attacks have primarily been targeting users in the Middle East using a specially crafted Excel spreadsheet.

"The hackers carefully constructed an Office document that remotely loaded Flash vulnerability. When the document was opened, all the exploit code and malicious payload were delivered through remote servers," Qihoo 360 published vulnerability analysis in a blog post.

The stack-based buffer overflow vulnerability, tracked as CVE-2018-5002, impacts Adobe Flash Player 29.0.0.171 and earlier versions on Windows, MacOS, and Linux, as well as Adobe Flash Player for Google Chrome, and can be exploited to achieve arbitrary code execution on targeted systems.

The vulnerability resides in the interpreter code of the Flash Player that handles static-init methods, which fails to correctly handle the exceptions for try/catch statements.


"Because Flash assumes that it is impossible to execute to the catch block when processing the try catch statement, it does not check the bytecode in the catch block," the researchers explain. "The attacker uses the getlocal, setlocal instruction in the catch block to read and write arbitrary addresses on the stack."

The registration date for a web domain, mimicking a job search website in the Middle East, used as the command and control (C&C) server for zero-day attacks suggests that hackers have been making preparations for the attack since February.

Besides the patch for CVE-2018-5002, Adobe also rolled out security updates for two "important" vulnerabilities—including Integer Overflow bug (CVE-2018-5000) and an Out-of-bounds read issue (CVE-2018-5001)—both of which lead to information disclosure.

So, users are highly recommended to immediately update their Adobe Flash Player to versions 30.0.0.113 via their update mechanism within the software or by visiting the Adobe Flash Player Download Center.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2018/06/flash-player-zero-day-exploit.html