Flash 0
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2014-8439 | Dereferenced Pointer Vulnerability in Adobe Flash Player Allows Code Execution CVE-2014-8439 is a memory-safety flaw (CWE-119) in Adobe Flash Player caused by the program's mishandling of a dereferenced memory pointer, allowing access to memory outside the intended bounds. As is typical of Flash memory-corruption bugs, it is triggered when Flash Player processes maliciously crafted content (e.g., a hostile .swf file rendered in a browser or embedded Flash player), which can crash the player or, more seriously, allow attacker-controlled code execution. A successful attacker gains the ability to run arbitrary code with the privileges of the logged-in user, a common route to workstation compromise and follow-on malware deployment. All Adobe Flash Player deployments were in scope at the time of the 2014 disclosure (the source data provides no version range), and because Flash reached end-of-life in December 2020, the population plausibly at risk today consists mainly of unmanaged or legacy endpoints, embedded/bundled enterprise applications, and installations still loading Flash content. Exploitation is confirmed in the wild: CISA added this CVE to the Known Exploited Vulnerabilities catalog on May 25, 2022, and its EPSS score of 20% (97th percentile) indicates a meaningful probability of ongoing or renewed exploitation despite the product's age. Do: Because Flash Player is end-of-life (since December 31, 2020) and no longer receives security updates, follow CISA's required action: uninstall Flash Player and any remaining browser plugins, or disconnect/isolate systems where it cannot yet be removed, and inventory third-party, intranet, and embedded applications that bundle Flash. Where Flash must remain temporarily, ensure the final release is installed (its post-EOL kill switch blocks most Flash content from running after January 12, 2021, which limits this attack vector), restrict Flash content to trusted sources, and prioritize monitoring given the KEV listing and 20% EPSS score. | — | 20% | KEV |
| masson the order of millions of legacy/embedded installations worldwide (Flash historically had 1 billion+ installs; residual post-EOL count unknown) | |
| CVE-2015-0310 | ASLR Protection-Mechanism Bypass in Adobe Flash Player CVE-2015-0310 is a protection-mechanism weakness in Adobe Flash Player in which the player fails to properly restrict the discovery of memory addresses, allowing an attacker to defeat Address Space Layout Randomization (ASLR), the mitigation that randomizes where code and data are loaded in memory. It is triggered by running attacker-controlled Flash (SWF) content in a browser, ActiveX control, or embedded player, typically as part of an exploit chain in which the attacker infers module addresses during a heap spray. The flaw grants no code execution by itself; its value to attackers is that it makes memory-corruption exploits deterministic and reliable, and it is generally chained with another Flash vulnerability to achieve remote code execution. Any system still running Adobe Flash Player is affected, a product now end-of-life, so exposure is concentrated in legacy enterprise web applications, kiosks, embedded players, and browser/OS builds that shipped with Flash bundled. CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2022-05-25, confirming exploitation in the wild; no public proof-of-concept is known, no CVSS score has been published, and EPSS estimates a 15.2% chance of exploitation within 30 days (97th percentile). Do: Per CISA's required action, treat Flash as retired: inventory all systems for Flash usage (browser plugins, IE/ActiveX controls, standalone players, and embedded enterprise applications) and remove or disconnect it where found. Where Flash must remain, ensure the latest available Adobe release is installed and restrict execution to trusted SWF content, prioritizing internet-facing endpoints given the KEV listing. | — | 15% | KEV |
| mass~1M-10M+ endpoints still running Flash in legacy enterprise apps, kiosks, or bundled-browser contexts | |
| CVE-2015-0311 | Use-After-Free Remote Code Execution in Adobe Flash Player CVE-2015-0311 is a use-after-free memory corruption flaw in Adobe Flash Player that Adobe patched in an emergency January 2015 release (APSB15-02); CISA catalogs it generically as an unspecified remote code execution vulnerability. It is triggered when a victim's Flash plugin processes maliciously crafted SWF content, typically embedded in a web page or delivered via malvertising and exploit kits such as Angler, and requires no authentication. A successful attacker gains arbitrary code execution in the context of the logged-in user, enabling malware installation; contemporaneous 2015 reporting tied Flash 0-day malvertising campaigns (e.g., Fessleak) to ransomware such as TeslaCrypt. Anyone running an affected Flash Player version in a browser or standalone install was exposed, but Flash Player has been end-of-life since the end of 2020, so the exposed population today consists of legacy, unmaintained systems. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-04-13 and carries an EPSS of 85.8% (100th percentile), although no public proof-of-concept is tracked. Do: Upgrade to the patched release from Adobe's January 2015 advisory — 16.0.0.296 (with 13.0.0.262 for the extended-support 13.x branch) — or, preferably, remove Flash entirely since it reached end-of-life on December 31, 2020; CISA's required action is to disconnect or retire any systems still running it. Check browsers, embedded devices, and internal applications for residual Flash plugins, and disable Flash or block SWF content as a mitigation where the plugin cannot be removed. | — | 86% | KEV |
| mass≈1 billion+ installs at the time of disclosure (near-universal desktop browser plugin); now limited to unmaintained EOL systems |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 46.105.251.7 | ith the attacks have been limited to two primary addresses (46.105.251.7 & 94.23.247.180). Below is a table illustrating domain name |
| ipv4 | 94.23.247.180 | have been limited to two primary addresses (46.105.251.7 & 94.23.247.180). Below is a table illustrating domain names recently used |
| sha256 | 1f6a4a3314b250e73a5649e2495ec131b27840d0948065f2a9c283a689a7b944 | 1/23/2015) IP Addresses: 46.105.251.7 94.23.247.180 SHA256: 1f6a4a3314b250e73a5649e2495ec131b27840d0948065f2a9c283a689a7b944 Conclusion Exploit kits continue to be a threat on your net |
Full article711 words · extracted from blog.talosintelligence.com · click to collapse
Friday, January 23, 2015 10:21
This post was authored by Nick Biasini, Earl Carter and Jaeson Schultz
Flash has long been a favorite target among Exploit Kits (EK). In October 2014 the Angler EK was believed to be targeting a new Flash vulnerability. The bug that the Angler exploit kit was attempting to exploit had been “accidentally” patched by Adobe’s APSB14-22 update. According to F-Secure, the vulnerability that Angler was actually attempting to exploit was an entirely new bug, CVE-2014-8439. The bug was severe enough that Adobe fixed it out-of-band.
Fast forward to January 2015. With the emergence of this new Flash 0-day bug, we have more evidence that the Angler Exploit Kit developers are actively working on discovering fresh bugs in Flash for themselves. The group is incorporating these exploits into the Angler EK *before* the bugs are publicized. Considering these 0-day exploits are being used alongside one of Angler’s preferred methods of distribution, malvertising, thus intensifying the potential for large-scale compromise.
On January 22, 2015, Adobe released update APSB15-02, which fixes CVE-2015-0310, a bypass of memory randomization mitigations in Flash. However, this new Flash bug is different, and is not fixed by APSB15-02. Adobe has sinced released a security advisory about a new Flash bug, CVE-2015-0311. According to Adobe, “this vulnerability is being actively exploited in the wild via drive-by-download attacks against systems running Internet Explorer and Firefox on Windows 8 and below.” This correlates nicely with Talos’ own data which suggests the EK is targeting specific browsers. We have seen evidence in telemetry of the 0-day only being served to specific User Agents. Chrome based or non-standard user agents are being served other exploits but the 0-day is being omitted. Unfortunately, a fix for CVE-2015-0311 will not be released until the week of January 26th.
There was a spike of traffic utilizing the 0-day beginning on January 20th, all of which were blocked by Cloud Web Security (CWS). Although this spike showed an increase in Angler related attacks, these attacks represent a small minority of the overall attack traffic. Based on our telemetry data we have seen domains associated with a single registrar being primarily responsible for the exploits being delivered. The approach appears to be rapid domain registration and exploitation with quick rotation of domains. Despite the rapid use of domains the IP’s associated with the attacks have been limited to two primary addresses (46.105.251.7 & 94.23.247.180). Below is a table illustrating domain names recently used by the group as well as several recently registered domains, that have yet to be seen. Most domains are registered one day, and then used for a short period of time beginning the following day. The majority of the domains are used for only 24 hours. Talos continues to see new domain registrations daily. A list of these domains compiled by Talos can be found here.
.
.

.
Indicators Of Compromise (IoCs)
Domain List (As of 1/23/2015)
IP Addresses:
46.105.251.7
94.23.247.180
SHA256:
1f6a4a3314b250e73a5649e2495ec131b27840d0948065f2a9c283a689a7b944
Conclusion
Exploit kits continue to be a threat on your network. Attackers are constantly updating the exploits used in their exploit kits in an attempt to gain access to more systems. Using techniques such as malvertising, these attacks can quickly be distributed to a wide audience. Identifying and stopping this evolving threat requires a layered security approach, which starts with applying security patches in a timely manner for third-party software, such as Flash. Breaking any step in the attack chain will successfully prevent this attack. Therefore, blocking network connections to known malicious content, as well as stopping malicious process activity are critical to combating the continuous threat imposed by exploit kits. SIDs: 29066, 31332, 33182, 33183, 33184, 33185 ,33186, 33187, 33188 Note: These SIDs represent the best information as of this post. Please refer to Defense Center or Snort.org for the most up-to-date signature information.
Protecting Users Against These Threats

Advanced Malware Protection (AMP) is ideally suited to prevent the execution of the malware used by these threat actors. CWS or WSA web scanning prevents access to malicious websites, including the downloading of the malware downloaded during these attacks. The Network Security protection of IPS and NGFW have up-to-date signatures to detect malicious network activity by threat actors.
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/flash-0-day-exploited-by-angler-exploit/