ZeroHour
Security Affairspublished ()ingested @securityaffairs

Adobe issued Out-of-Band Flash Update for CVE-2014

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-0569

NVD description · AI analysis pending
92%
CVE-2014-8439
Dereferenced Pointer Vulnerability in Adobe Flash Player Allows Code Execution

CVE-2014-8439 is a memory-safety flaw (CWE-119) in Adobe Flash Player caused by the program's mishandling of a dereferenced memory pointer, allowing access to memory outside the intended bounds. As is typical of Flash memory-corruption bugs, it is triggered when Flash Player processes maliciously crafted content (e.g., a hostile .swf file rendered in a browser or embedded Flash player), which can crash the player or, more seriously, allow attacker-controlled code execution. A successful attacker gains the ability to run arbitrary code with the privileges of the logged-in user, a common route to workstation compromise and follow-on malware deployment. All Adobe Flash Player deployments were in scope at the time of the 2014 disclosure (the source data provides no version range), and because Flash reached end-of-life in December 2020, the population plausibly at risk today consists mainly of unmanaged or legacy endpoints, embedded/bundled enterprise applications, and installations still loading Flash content. Exploitation is confirmed in the wild: CISA added this CVE to the Known Exploited Vulnerabilities catalog on May 25, 2022, and its EPSS score of 20% (97th percentile) indicates a meaningful probability of ongoing or renewed exploitation despite the product's age.

Do: Because Flash Player is end-of-life (since December 31, 2020) and no longer receives security updates, follow CISA's required action: uninstall Flash Player and any remaining browser plugins, or disconnect/isolate systems where it cannot yet be removed, and inventory third-party, intranet, and embedded applications that bundle Flash. Where Flash must remain temporarily, ensure the final release is installed (its post-EOL kill switch blocks most Flash content from running after January 12, 2021, which limits this attack vector), restrict Flash content to trusted sources, and prioritize monitoring given the KEV listing and 20% EPSS score.

20% KEV
  • Adobe Flash Player
masson the order of millions of legacy/embedded installations worldwide (Flash historically had 1 billion+ installs; residual post-EOL count unknown)

Indicators of compromiseAll →

TypeIndicatorContext
ipv415.0.0.152rability which was successfully exploited with Flash Player 15.0.0.152 but not with 15.0.0.189. That would imply the vulnerability
ipv415.0.0.239ayer to the latest version of Windows and Apple’s Mac OS is 15.0.0.239, and the latest for Linux is 11.2.202.424, anyway it is pos
Full article416 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 26, 2014

Adobe has released yesterday an out-of-band update to fix a critical remote code-execution vulnerability CVE-2014-8439 in Flash Player that is being exploited in the wild.

Adobe has released an emergency patch to patch a critical remote code-execution vulnerability (CVE-2104-8439) affecting Flash Player that was already fixed last month (Adobe’s Oct. 14th), but that was exploited again. According to an Adobe Security Bulletin, the update implements a mitigating solution for the CVE-2104-8439 that affects the Adobe Flash and could be exploited by attackers to install malware.

The critical vulnerability in Flash Player for Windows, Mac and Linux was mitigated in October 14 for the first time, but the French researcher Kafeine discovered evidence of the exploits in the Angler, Astrum and Nuclear malware kits after Adobe released the patch. It is likely that the attackers were able to reverse-engineering the patch issued by Adobe and include it in commercial available exploits.

“The vulnerability is being exploited in blind mass attack. No doubt about it : the team behind Angler is really good at what it does,” Kafeine said in a blog post.

The Flash Player to the latest version of Windows and Apple’s Mac OS is 15.0.0.239, and the latest for Linux is 11.2.202.424, anyway it is possible to install the patch manually from Adobe. Timo Hirvonen, a senior researcher at F-Secure, confirmed that its company has received an exploit sample from Kaffeine and that they verified that the exploit was working despite the deployment of the Adobe fixed in October.

“We discovered the vulnerability while analyzing a Flash exploit from an exploit kit called Angler. We received the sample from Kafeine, a renowned exploit kit researcher. He asked us to identify the vulnerability which was successfully exploited with Flash Player 15.0.0.152 but not with 15.0.0.189. That would imply the vulnerability was something patched in APSB14-22. However, based on the information that we had received via Microsoft Active Protections Program the exploit didn’t match any of the vulnerabilities patched in APSB14-22 (CVE-2014-0558, CVE-2014-0564, or CVE-2014-0569).
We considered the possibility that maybe the latest patch prevented the exploit from working and the root cause of the vulnerability was still unfixed so we contacted the Adobe Product Security Incident Response Team.” reported F-Secure in a blog post.

Users can install the new update from Adobe Flash Player Download Center, or using the automated update requested by the Adobe solution.

Pierluigi Paganini

(Security Affairs –  Adobe patch, CVE-2104-8439)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/30552/security/adobe-issued-band-flash-player-update-cve-2014-8439.html