ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

The mysterious case of CVE-2016-0034: the hunt for a Microsoft Silverlight 0

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-0497
Integer Underflow Remote Code Execution in Adobe Flash Player

CVE-2014-0497 is an integer underflow (CWE-191) in Adobe Flash Player that allows a remote attacker to execute arbitrary code, triggered when the player processes specially crafted Flash content, such as that embedded in a malicious web page. Successful exploitation gives the attacker code execution on the victim system in the context of the Flash Player process. At the time of the 2014 disclosure, essentially every deployed Adobe Flash Player installation was potentially affected, making the population of exposed systems enormous, though Flash has since reached end-of-life and is no longer patched. CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2024-09-17, indicating confirmed in-the-wild exploitation; no public proof-of-concept is documented and ransomware association is listed as unknown. EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile), so any residual Flash deployment should be treated as high risk.

Do: Because Adobe Flash Player is end-of-life/end-of-service and no longer receives security updates, CISA's required action is to discontinue use: uninstall Flash Player, disable or remove Flash plugins from browsers, and audit legacy Windows systems and intranet applications for residual Flash components. Since Flash is EOL, do not rely on patching alone — blocking SWF content delivery and removing the runtime are the durable mitigations; prioritize any systems that still render Flash from untrusted sources given the 99.9% EPSS score and KEV listing.

100% KEV
  • Adobe Flash Player
massHundreds of millions to ~1 billion+ installations at the time of disclosure; current exposure limited to unpatched legacy systems and unknown in count
CVE-2014-0546
Sandbox Bypass in Adobe Reader and Acrobat on Windows

Adobe Reader and Acrobat on Windows contain a sandbox bypass (CVE-2014-0546) in which an attacker can defeat the application's sandbox protection mechanism and execute native code in a privileged context. The source data does not specify the exact trigger, but PDF-reader sandbox escapes are normally exploited by getting a user to process attacker-supplied PDF content and are typically chained with a PDF-parsing bug to reach full code execution outside the sandbox. Successful exploitation gives an attacker native code execution beyond the sandbox's restrictions, materially increasing the impact of any accompanying PDF exploit. Only Windows installations of Adobe Reader and Acrobat are identified as affected in the available data. The flaw is known to be exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-05-25 (ransomware use unknown), EPSS estimates a 22.3% probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known.

Do: Inventory Windows endpoints for Adobe Reader and Acrobat and update them to the latest patched release per Adobe's security bulletin, per CISA's required action (patching is mandatory for U.S. federal agencies given the KEV listing). Because the flaw defeats the sandbox itself, there is no strong configuration-only mitigation, so patching is the primary control; prioritize endpoints that open untrusted PDFs and verify afterwards that no legacy unpatched builds remain.

22% KEV
  • Adobe Reader (Windows)
  • Adobe Acrobat (Windows)
massHundreds of millions of Windows users potentially exposed (Adobe Reader/Acrobat ubiquity); count of endpoints still running vulnerable legacy builds unknown,…
CVE-2015-2360
Win32k Local Privilege Escalation in Microsoft Windows Kernel Drivers

CVE-2015-2360 is a memory-handling flaw (CWE-119) in Win32k.sys, the Windows kernel-mode driver, that allows a local user to elevate privileges or cause a denial-of-service crash. It is triggered by local code that drives Win32k into improperly handling objects in memory, letting the attacker run code with kernel/SYSTEM-level rights — typically chained with a separate remote code execution bug to go from network access to full system compromise. Any Microsoft Windows system that has not received the vendor fix is affected, and because the fix shipped in mid-2015, the remaining exposed population is largely legacy Windows deployments that missed regular patching. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-25, indicating exploitation in the wild, and EPSS assigns a 15% probability of exploitation within 30 days (96th percentile); no public proof-of-concept is known.

Do: Apply the Microsoft update from security Bulletin MS15-078 (July 2015) to any Windows system lacking it, prioritizing internet-facing hosts running legacy Windows/Server releases and POS, embedded or air-gapped systems that miss routine patch cycles. Verify via patch inventory that the affected Win32k.sys builds are current, and treat the CISA KEV listing as mandatory remediation per the required action (apply updates per vendor instructions).

15% KEV
  • Microsoft Win32k.sys / Windows kernel-mode drivers (Microsoft Windows) All supported Windows releases of the era — Windows Vista SP2, Windows 7 SP1, Windows 8, Windows 8.1, Windows RT 8.1, Windows Server 2008 SP2, Server 2008 R2 SP
massplausibly millions of legacy Windows systems remain unpatched, out of a multi-hundred-million to >1 billion Windows install base
CVE-2016-0034
Remote Code Execution via Crafted Website in Microsoft Silverlight 5

CVE-2016-0034 is a memory-corruption flaw in the Microsoft Silverlight 5 runtime, which mishandles negative offsets during decoding, corrupting object headers. An attacker triggers it by convincing a user to visit a crafted website while the vulnerable Silverlight plug-in is active in their browser, requiring no privileges but user interaction. Successful exploitation allows the attacker to execute arbitrary code in the context of the logged-in user (or crash the browser/application). Anyone running Microsoft Silverlight 5 versions before 5.1.41212.0 is affected; Silverlight is now end-of-life, so remaining installations are legacy deployments. The flaw was exploited in the wild through exploit kits such as Angler and RIG to deliver ransomware like Cerber, and it was added to the CISA KEV catalog in May 2022 with known ransomware use.

Do: Upgrade Silverlight to version 5.1.41212.0 (January 2016 security update) on any system where it remains installed. Because Silverlight is end-of-life, CISA's KEV required action is to disconnect or remove it and migrate any legacy Silverlight-based web applications; prioritize internet-facing endpoints and users of Internet Explorer/legacy browsers, where the plug-in can still be invoked.

8.870% KEV ransomware
  • microsoft Silverlight Silverlight 5 before 5.1.41212.0 (fixed in 5.1.41212.0, January 2016 Patch Tuesday)
masshistorically hundreds of millions of installs (Silverlight reached roughly 70% of consumer devices at peak); residual active installs today likely number in…

Indicators of compromiseAll →

TypeIndicatorContext
md5df990a98eef1d6c15360e70d3c1ce05ee in the archive is: SilverApp1.dll: Size: 17920 bytes md5: df990a98eef1d6c15360e70d3c1ce05e This is the actual DLL that implements the Silverlight expl
Full article1,395 words · extracted from securelist.com · click to collapse

Perhaps one of the most explosively discussed subjects of 2015 was the compromise and data dump of Hacking Team, the infamous Italian spyware company.

For those who are not familiar with the subject, Hacking Team was founded in 2003 and specialized in selling spyware and surveillance tools to governments and law enforcement agencies. On July 5, 2015, a large amount of data from the company was leaked to the Internet with a hacker known as “Phineas Fisher” claiming responsibility for the breach. Previously, “Phineas Fisher” did a similar attack against Gamma International, another company in the spyware/surveillance business.

The hacking of Hacking Team was widely discussed in the media from many different points of view, such as the legality of selling spyware to oppressive governments, the quality (or lack of…) of the tools and leaked email spools displaying the company’s business practices.

One of these stories attracted our attention.

How a Russian hacker made $45,000 selling a 0-day Flash exploit to Hacking Team

So reads the title of a fascinating article written for Ars Technica by Cyrus Farivar on July 10, 2015. The article tells the story of Vitaliy Toropov, a 33-year-old exploit developer from Moscow who made a living by selling zero-day vulnerabilities to companies such as Hacking Team.

In the Ars Technica article, Cyrus writes the following paragraph, which shows the original offer from the exploit seller:

Excerpt from the Ars Technica article

For a company like Hacking Team, zero-days are their “bread and butter” — their software cannot infect their targets without effective exploits and zero-days, especially those that can bypass modern defense technologies such as ASLR and DEP. Those exploits are in very high demand.

The trade between these two continued until they finally agreed on purchasing an Adobe Flash Player zero-day, now defunct, for which Vitaliy Toropov promptly received a $20,000 advance payment.

A good salesman, Vitaliy Toropov immediately mailed back and offered a discount on the next purchases. So writes Cyrus, in his Ars Technica story:

Excerpt from the Ars Technica article

This section of the story immediately spiked our attention. A Microsoft Silverlight exploit written more than two years ago and may survive in the future? If that was true, it would be a heavyweight bug, with huge potential to successfully attack a lot of major targets. For instance, when you install Silverlight, it not only registers itself in Internet Explorer, but also in Mozilla Firefox, so the attack vector could be quite large.

The hunt for the Silverlight zero-day

In the past, we successfully caught and stopped several zero-days, including CVE-2014-0515 and CVE-2014-0546 (used by the Animal Farm APT group), CVE-2014-0497 (used by the DarkHotel APT group) and CVE-2015-2360 (used by the Duqu APT group). We also found CVE-2013-0633 a FlashPlayer zero-day that was used by Hacking Team and another unknown group.

We strongly believe that discovery of these exploits and reporting them to the affected software manufacturers free of charge makes the world a bit safer for everyone.

So while reading the Ars Technica story, the idea to catch Vitaliy Toropov’s unknown Silverlight exploit materialized.

How does one catch zero-days in the wild? In our case, we rely on several well-written tools, technologies and our wits. Our internal tools include KSN (Kaspersky Security Network) and AEP (Automatic Exploit Prevention).

To catch this possibly unknown Silverlight exploit we started by investigating the other exploits written by Vitaliy Toropov. Luckily, Vitaliy Toropov has a rather comprehensive profile on OVSDB. Additionally, PacketStorm has a number of entries from him:

This one caught our attention for two reasons:

  • It is a Silverlight exploit
  • It comes with a proof of concept written by Vitaly himself

One can easily grab the PoC from the same place:

Which we did.

The archive contains a well-written readme file that describes the bug, as well as source codes for the PoC exploit.

The exploit in this PoC simply fires up calc.exe on the victim’s machine. The archive includes a debug version compiled by the author, which is extremely useful to us, because we can use it to identify specific programming techniques such as specific strings or shellcode used by the developer.

The most interesting file in the archive is:

SilverApp1.dll:
Size: 17920 bytes
md5: df990a98eef1d6c15360e70d3c1ce05e

This is the actual DLL that implements the Silverlight exploit from 2013, as coded by Vitaliy Toropov.

With this file in hand, we decided to build several special detections for it. In particular, we wrote a YARA rule for this file which took advantage of several of the specific strings from the file. Here’s what our detection looked like in YARA:

Pretty straightforward, no?

Actually, nowadays we write YARA rules for all high-profile cases and we think it’s a very effective way to fight cyberattacks. Great props to the Victor Manuel Alvarez and the folks at VirusTotal (now Google) for creating such a powerful and versatile tool!

The long wait…

After implementing the detection, we waited, hoping that an APT group would use it. Since Vitaliy Toropov was offering it to Hacking Team, we also assumed that he sold it to other buyers, and what good is a zero-day if you don’t use it?

Unfortunately, for several months, nothing happened. We had already forgotten about this until late November 2015.

On November 25th, one of our generic detections for Toropov’s 2013 Silverlight exploit triggered for one of our users. Hours later, a sample was also uploaded to a multiscanner service from Lao People’s Democratic Republic (Laos).

This file was compiled in July 21, 2015, which is about two weeks after the Hacking Team breach. This also made us think it was probably not one of the older 2013 exploits but a new one.

It took us some time to analyse and understand the bug. When we were absolutely sure it was indeed a new zero-day exploit, we disclosed the bug to Microsoft.

Microsoft confirmed the zero-day (CVE-2016-0034) and issued a patch on January 12, 2016.

Technical analysis of the bug:

The vulnerability exists in the BinaryReader class. When you create an instance of this class you can pass your own realization of the encoding process:

Moreover, for the Encoding process you can use your own Decoder class:

Looking at the BinaryReader.Read() code, we see the following:

Indeed, the “index” value was checked correctly before this call:

But if you will look deeper inside InternalReadChars (this function is marked as unsafe and it is using pointers manipulations) function you will see the following code:

The problem appears because the GetChars function could be user-defined, for instance:

Therefore, as you can see we can control the “index” variable from user-defined code. Let’s do some debugging.

This is a Test.buf variable, where 05 is the array length before triggering the vulnerability:

After calling BinaryRead.Read method we are stopping in InternalReadChars method (index is 0):

After this call we stopped in user-defined code:

This is a first call of user-defined function and we return incorrect value from it. In the next iteration, the “index” variable contains the incorrect offset:

After we change the offset we can easily modify memory, for instance:

This is a Test.buf object after our modifications in decoder method:

So, is this the droid you’ve been looking for?

One of the biggest questions we have is whether this is Vitaliy Toropov’s Silverlight zero-day which he tried to sell to Hacking Team. Or is it a different one?

Several things make us think it’s one of his exploits, such as the custom error strings. Of course, there is no way to be sure and there might be several Silverlight exploits out there. One thing is for sure though – the world is a bit safer with the discovery and patching of this one.

One final note: due to copyright reasons, we couldn’t check if the leaked Hacking Team archive has this exploit as well. We assume the security community which found the other zero-days in the HackingTeam leaks will also be able to check for this one.

If you’d like to learn how to write effective YARA rules and catch new APTs and zero-days, why not take our elite YARA training before SAS 2016? Hunt APTs with Yara like a GReAT Ninja (with trainers Costin Raiu, Vitaly Kamluk and Sergey Mineev). The class is almost sold out!

Kaspersky products detect new Silverlight exploit as HEUR:Exploit.MSIL.Agent.gen.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/the-mysterious-case-of-cve-2016-0034-the-hunt-for-a-microsoft-silverlight-0-day/73255/