ZeroHour
Cisco Talospublished ()ingested

CVE-2012-1535: Flash 0

criticalVulnerability exploited in the wildimportance 60CVE-2012-1535

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2012-1535
Arbitrary Code Execution via Crafted SWF Content in Adobe Flash Player (EOL)

CVE-2012-1535 is an unspecified vulnerability in Adobe Flash Player that allows remote attackers to execute arbitrary code or cause a denial of service when the player processes specially crafted SWF content. It is typically triggered when a user opens a web page, advertisement, or document that embeds the hostile SWF file. A successful exploit gives the attacker code execution in the context of the user running Flash, enabling full system compromise; a failed or partial exploit can crash the player. Anyone still running unpatched Adobe Flash Player is affected, and because the product is end-of-life and no longer receives security updates, CISA's required action is to disconnect or remove it if still in use. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-03-03 (ransomware use unknown), and EPSS assigns a 70.4% probability of exploitation within 30 days, though no public proof-of-concept is known.

Do: Audit the environment for any remaining Flash Player usage — browser plugins, standalone projectors, and SWF content embedded in legacy intranet applications, kiosks, and e-learning tools — and remove or disconnect it, per CISA's required action for this EOL product. If Flash content must be retained, isolate it from untrusted sources (block .swf at the gateway, do not load remote SWF) and plan migration to modern alternatives. No vendor patch will be issued, so remediation means removal, not upgrading.

70% KEV
  • Adobe Flash Player
mass≈1M+ residual installations worldwide (Flash was historically installed on virtually every desktop; EOL since December 2020)
Full article302 words · extracted from blog.talosintelligence.com · click to collapse

Thursday, August 16, 2012 10:03

Yesterday Adobe released APSB12-18, which addressed CVE-2012-1535. As noted in the Adobe bulletin, the vulnerability has been actively exploited in the wild, though primarily in targeted attacks wrapped in Microsoft Word documents.

The VRT was able to obtain a sample of one of the documents that has been circulating in the wild, and has created several new rules that detect it. While the vulnerability itself is complex - as are most Flash issues - there are several extremely obvious indicators of malicious intent in the file, including plaintext strings and several unencoded, unobfuscated characters commonly associated with heap spray techniques. Given that even compressing the Flash - which is trivial to do, and commonly found in the field - would have obscured these indicators, we're a bit puzzled as to why the actors behind these attacks chose not to do so, particularly since sending such an obviously malicious file presented them with the risk of having their 0-day attack discovered.

We've released several new rules today to detect this attack. SIDs 23853 and 23854 look for the underlying vulnerability, and 23856 and 23857 will detect the specific Flash files used in the document mentioned above. SIDs 23857 - 23862 look for different variants of the heap spray bytes used in this attack, that are common in other attacks in the field.

It's also worth noting that SIDs 18546 or 18549 (depending on the delivery mechanism - HTTP vs. SMTP, respectively), which look for Flash files embedded in Word documents, would have caught this attack prior to discovery by any party. While there are occasional legitimate uses for such documents, you may wish to consider enabling those rules in your particular environment - especially if you're willing to trade 0-day detection for the occasional false positive.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/cve-2012-1535-flash-0-day-in-wild/