ZeroHour
Recorded Futurepublished ()ingested S3

New Kit, Same Player: Top 10 Vulnerabilities Used by Exploit Kits in 2016

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2015-0313
Use-After-Free Remote Code Execution in Adobe Flash Player

CVE-2015-0313 is a use-after-free (CWE-416) flaw in Adobe Flash Player that allows remote attackers to execute arbitrary code. It is triggered when the Flash browser plugin processes specially crafted Flash/SWF content, commonly delivered through a malicious or malvertising-loaded web page or exploit kit, causing the plugin to reference freed memory. A successful attack yields code execution in the context of the logged-in user, which related 2015 coverage links to exploit kit (e.g., RIG) and malvertising campaigns delivering ransomware. Anyone running a then-current Adobe Flash Player in a browser was affected; the source data does not specify exact version ranges. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-13), has an EPSS exploitation probability of 95.3% (100th percentile), and should be treated as actively exploited in the wild.

Do: Apply Adobe's January 2015 emergency security bulletin (APSB15-04), which addressed this flaw, if any system must still run Flash; otherwise upgrade to the latest available patched release. Because Flash is end-of-life, CISA's required action is to disconnect or fully remove/uninstall Flash wherever it is still in use. Audit browsers, legacy web applications, and any software that renders SWF content, and review endpoint logs for exploit kit or malvertising-driven infections.

95% KEV
  • Adobe Flash Player
mass~hundreds of millions of installations at the time of disclosure (Flash was near-ubiquitous in browsers); only a small legacy footprint remains today
CVE-2015-1671
TrueType Font Parsing RCE in Microsoft Windows, .NET, Office, Lync, and Silverlight

CVE-2015-1671 is a remote code execution vulnerability in components of Microsoft Windows, .NET Framework, Office, Lync, and Silverlight that fail to properly handle TrueType fonts. An attacker triggers it by getting a victim's system to process a specially crafted TrueType font embedded in delivered content, such as a document or web-borne material, which is a classic exploit-kit delivery vector. Successful exploitation yields arbitrary code execution on the affected machine, giving the attacker control at the privileges of the affected process and a path to full system compromise. Any Windows environment running unpatched versions of the affected components is exposed, with CISA specifically listing Microsoft Windows as the affected product. Exploitation is confirmed in the wild: the flaw is in the CISA Known Exploited Vulnerabilities catalog (added 2022-05-25) and carries a 54.6% EPSS probability of exploitation within 30 days (99th percentile), though no public PoC is cataloged and ransomware use is listed as unknown.

Do: Apply the May 2015 Microsoft security updates (MS15-044 for Windows font drivers, .NET Framework, Office, and Silverlight, and the related Lync/Silverlight update MS15-049) across all workstations and servers, as CISA's KEV required action mandates patching per vendor instructions. Because exploit kits historically delivered this flaw via web-borne content, prioritize user-facing systems and verify that Silverlight and .NET Framework font-parsing fixes are installed, not just OS-level patches; hosts with no supported patch path should restrict rendering of untrusted documents and web content.

55% KEV
  • Microsoft Windows
  • Microsoft .NET Framework
  • Microsoft Office
  • +2 more
masshundreds of millions of Windows endpoints/users worldwide, plus every Office/.NET/Silverlight/Lync install on unpatched systems
CVE-2015-2419
Memory Corruption RCE in Microsoft Internet Explorer JScript Engine

CVE-2015-2419 is a memory corruption flaw (CWE-119) in the JScript engine used by Microsoft Internet Explorer, allowing remote attackers to execute arbitrary code or cause a denial of service through a crafted website. It is triggered when a user visits an attacker-controlled page whose JScript content corrupts memory in the affected browser process. A successful attacker gains remote code execution in the context of the logged-on user (or crashes the browser), which makes drive-by and exploit-kit delivery routes viable. Any Windows user running the affected versions of Internet Explorer at the time of disclosure was exposed, and Microsoft shipped fixes as part of its July 2015 security updates. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28), carries a 53.4% EPSS (99th percentile), and related reporting places it among the top vulnerabilities used by exploit kits in 2015-2016.

Do: Apply Microsoft's July 2015 security updates for Internet Explorer per vendor instructions, as required by the CISA KEV catalog, and verify that any legacy Windows systems still running Internet Explorer have received them. Because exploitation typically occurs via drive-by web attacks, retire or fully patch IE on client endpoints and keep endpoint protection enabled to catch exploit-kit delivery. Confirm no workstations remain on unpatched IE builds, since this entry has been in CISA KEV since March 2022 and exploitation probability remains high (EPSS 53.4%).

53% KEV
  • Microsoft Internet Explorer
masshundreds of millions of Windows users running Internet Explorer at the time of disclosure
CVE-2015-5119
Use-After-Free RCE in Adobe Flash Player (ActionScript 3 ByteArray)

CVE-2015-5119 is a use-after-free memory-corruption vulnerability (CWE-119) in the ActionScript 3 ByteArray class of Adobe Flash Player. It is triggered when Flash processes crafted ActionScript/SWF content — typically a malicious .swf loaded from a web page, advertisement, email attachment, or document — causing Flash to access already-freed memory in an attacker-controllable way. A successful attack gives the adversary remote code execution in the context of the user running Flash. Anyone with Adobe Flash Player installed was exposed; at disclosure Flash was on the vast majority of internet-connected desktops, and today risk is concentrated in legacy browsers, office/document tooling, industrial or enterprise applications, and other systems where Flash was never removed. Exploitation status: this flaw has long-standing in-the-wild use (related headlines tie the leaked Hacking Team Flash exploit to APT campaigns against Japanese, East Asian, and US Government targets and to top 2016 exploit kits), it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03; ransomware use unknown), and EPSS assigns a 99.3% probability of exploitation within 30 days.

Do: Because Flash Player is end-of-life, CISA's required action is to disconnect it rather than patch: audit browsers, document/office tooling, and legacy or industrial applications for Flash dependencies and fully uninstall or disable Flash and any embedded SWF players. If a system must keep Flash temporarily, verify it runs a patched build from 2015 or later (Adobe's July 2015 emergency update, APSB15-16, addressed this flaw) and block untrusted SWF content via browser settings, email gateway, and web filtering. Prioritize cleanup on internet-facing endpoints and users who browse the web or open untrusted email attachments, the typical delivery route for this exploit.

99% KEV
  • Adobe Flash Player
mass≈ millions of legacy desktop installations
CVE-2015-5122
Use-After-Free RCE in Adobe Flash Player AS3 DisplayObject

CVE-2015-5122 is a use-after-free vulnerability (CWE-416) in the DisplayObject class of the ActionScript 3 implementation in Adobe Flash Player. It is triggered when the Flash runtime processes crafted AS3/SWF content, typically a malicious Flash file loaded from a web page or delivered via an exploit kit, causing freed memory to be reused and letting a remote attacker execute arbitrary code in the user's context or crash the player (denial of service). Any system or browser still running affected Flash Player builds is affected; because Flash has reached end-of-life and no longer receives updates, environments that still rely on it are the primary at-risk population. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-04-13, related reporting shows it used by exploit kits and in watering-hole attacks, and EPSS assigns a 93.7% probability of exploitation within 30 days.

Do: Follow CISA's required action: uninstall or disconnect Adobe Flash Player wherever it is still in use, since the product is end-of-life and receives no further patches. Inventory browsers, legacy web applications, and bundled software for residual Flash plug-ins and SWF content, and disable Flash content loading where immediate removal is not possible. For systems that must keep running Flash, isolate them and block exposure to untrusted web content, as drive-by exploit kit delivery was the observed attack pattern.

94% KEV
  • Adobe Flash Player
mass~1 billion+ historical installs (Flash ran on most internet-connected PCs at the 2015 disclosure); current residual post-EOL base unknown
Full article853 words · extracted from recordedfuture.com · click to collapse

Analysis Summary

  • Adobe Flash Player provided eight of the top 10 vulnerabilities used by exploit kits in 2015.
  • Vulnerabilities in Microsoft’s Internet Explorer and Silverlight are also major targets.
  • Angler is currently the most popular exploit kit, regularly tied to malware including Cryptolocker.
  • Identifying targeted vulnerabilities can better inform patch management functions within organizations.
  • Some security professionals suggest uninstalling Adobe Flash Player. Enabling “Click to Play” is a stop-gap.

Recorded Future threat intelligence analysis of over 100 exploit kits (EKs) and known vulnerabilities identified Adobe Flash Player as the most frequently exploited product. While the role of Adobe Flash vulnerabilities as a regular in-road for criminals and malware should come as no surprise to information security professionals, the scale is significant.

According to Web analysis from January 1, 2015 to September 30, 2015, Adobe Flash Player comprised eight of the top 10 vulnerabilities leveraged by exploit kits. Other leveraged vulnerabilities affect Microsoft Internet Explorer versions 10 and 11 (CVE-2015-2419) and Microsoft products including Silverlight (CVE-2015-1671).

Background

Exploit kits are crimeware as a service (CaaS) where users pay per install of their malware. Users only need to provide the payload (malware such as Cryptolocker) and a means to distribute the generated URL. This URL can be spread through compromised sites or malicious third-party advertising (malvertising). The teams behind these exploit kits continue to add fresh exploits for software as increased effectiveness in delivering the “customer’s” payload will generate more revenue.

Exploit kit victims load the compromised Web page, malvertisement or unwittingly follow a malicious link to the exploit kit’s landing page. Per Sophos, “the landing page is the starting point for the exploit kit code.” Using a mix of HTML and JavaScript, the EK identifies the visitor’s browser and plugins, providing the kit the information necessary to deploy the exploit most likely to result in a drive-by download.

Understanding what vulnerabilities are targeted by exploit kits can better inform patch management functions within organizations.

Angler Exploit Kit in Focus

Angler is one of the most popular and well-known exploit kits, linked to several high-profile malvertising and ransomware campaigns. First appearing in 2013, it quickly overtook Blackhole as a favorite of cyber criminals, likely due to the rapid pace of new exploit adoption and its ability to evade many antivirus products.

Recorded Future analysis of Web sources including social media, forums and technical reporting highlighted Angler payloads including Cryptowall, AlphaCrypt, Necurs, and Bedep malware.

Click image for larger view.

In October, Cisco claimed to strike a blow to Angler as they found a large batch of Angler proxy servers which accounted for up to 50 percent of the exploit kit’s activity. This infrastructure reportedly targeted up to 90,000 victims a day and generated over $30 million a year.

Methodology

Recorded Future analyzed thousands of sources from the Web including .onion site, criminal forums and social media. Analysis focused on exploit kit and vulnerability discussion from January 1, 2015 to September 30, 2015. As part of this research, Recorded Future utilized a list of 108 exploit kits which included well-known EKs such as Angler, Neutrino, Nuclear Pack, etc. Top EK exploited vulnerabilities were ranked by the number of Web references linking them to an exploit kit.

Recorded Future did not reverse engineer any malware mentioned in this analysis and instead performed a meta-analysis of available information from information security blogs, forum postings, etc. Exploits for dozens of other vulnerabilities are currently employed by EKs and this article’s intent is to highlight top targets of popular exploit kits.

Results

Using this methodology, Recorded Future identified the top vulnerabilities used by exploit kits. Adobe Flash Player vulnerabilities dominated this list with thousands of references.

The top vulnerability CVE 2015-0313 – affecting Flash Player 16.0.0.296 and identified by Adobe as critical – was patched on February 2, 2015 and seen as a zero day exploit as early as December 2014. Recorded Future observed 410 references of CVE-2015-0313 tied to an exploit kit in 2015. This vulnerability has recently been seen in the Hanjuan, Angler and Fiesta EKs.

Exploits tied to the third and fifth most mentioned vulnerabilities (CVE-2015-5119, CVE-2015-5122) were immediately added to EKs including Angler following their disclosure as a Adobe Flash zero-days in the July 2015 Hacking Team leak.

Click image for larger view.

Impact

Popular due to compatibility across browsers and operating systems, Adobe Flash Player’s recent string of vulnerabilities, and popularity with APT groups such as Pawn Storm, calls into question Flash’s place in a secure operating environment.

Flash versions older than 19.0.0.226 (or 18.0.0.255 on older machines) are now actively restricted from running on Apple OS X. Brian Krebs recently wrote about going a month without Flash. In July, WIRED discussed the Occupy Flash movement and detailed its long line of issues.

Click image for larger view.

Conclusion

While each organization needs to decide for itself if installing the steady stream of Adobe Flash updates is feasible, steps can be taken as a stop-gap to Adobe exploits. This includes enabling “Click to Play” which provides a check on use of Adobe Flash Player in an unknown environment.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/blog/top-vulnerabilities-2015