Hacking Team Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2014-0497 | Integer Underflow Remote Code Execution in Adobe Flash Player CVE-2014-0497 is an integer underflow (CWE-191) in Adobe Flash Player that allows a remote attacker to execute arbitrary code, triggered when the player processes specially crafted Flash content, such as that embedded in a malicious web page. Successful exploitation gives the attacker code execution on the victim system in the context of the Flash Player process. At the time of the 2014 disclosure, essentially every deployed Adobe Flash Player installation was potentially affected, making the population of exposed systems enormous, though Flash has since reached end-of-life and is no longer patched. CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2024-09-17, indicating confirmed in-the-wild exploitation; no public proof-of-concept is documented and ransomware association is listed as unknown. EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile), so any residual Flash deployment should be treated as high risk. Do: Because Adobe Flash Player is end-of-life/end-of-service and no longer receives security updates, CISA's required action is to discontinue use: uninstall Flash Player, disable or remove Flash plugins from browsers, and audit legacy Windows systems and intranet applications for residual Flash components. Since Flash is EOL, do not rely on patching alone — blocking SWF content delivery and removing the runtime are the durable mitigations; prioritize any systems that still render Flash from untrusted sources given the 99.9% EPSS score and KEV listing. | — | 100% | KEV |
| massHundreds of millions to ~1 billion+ installations at the time of disclosure; current exposure limited to unpatched legacy systems and unknown in count | |
| CVE-2015-5119 | Use-After-Free RCE in Adobe Flash Player (ActionScript 3 ByteArray) CVE-2015-5119 is a use-after-free memory-corruption vulnerability (CWE-119) in the ActionScript 3 ByteArray class of Adobe Flash Player. It is triggered when Flash processes crafted ActionScript/SWF content — typically a malicious .swf loaded from a web page, advertisement, email attachment, or document — causing Flash to access already-freed memory in an attacker-controllable way. A successful attack gives the adversary remote code execution in the context of the user running Flash. Anyone with Adobe Flash Player installed was exposed; at disclosure Flash was on the vast majority of internet-connected desktops, and today risk is concentrated in legacy browsers, office/document tooling, industrial or enterprise applications, and other systems where Flash was never removed. Exploitation status: this flaw has long-standing in-the-wild use (related headlines tie the leaked Hacking Team Flash exploit to APT campaigns against Japanese, East Asian, and US Government targets and to top 2016 exploit kits), it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03; ransomware use unknown), and EPSS assigns a 99.3% probability of exploitation within 30 days. Do: Because Flash Player is end-of-life, CISA's required action is to disconnect it rather than patch: audit browsers, document/office tooling, and legacy or industrial applications for Flash dependencies and fully uninstall or disable Flash and any embedded SWF players. If a system must keep Flash temporarily, verify it runs a patched build from 2015 or later (Adobe's July 2015 emergency update, APSB15-16, addressed this flaw) and block untrusted SWF content via browser settings, email gateway, and web filtering. Prioritize cleanup on internet-facing endpoints and users who browse the web or open untrusted email attachments, the typical delivery route for this exploit. | — | 99% | KEV |
| mass≈ millions of legacy desktop installations |
Full article597 words · extracted from securityaffairs.com · click to collapse

Security experts at Trend Micro revealed that one of the exploits discovered in the Hacking Team package tied to Attacks In Korea and Japan.
Following the recent hack of the popular surveillance firm Hacking Team, the experts started the analysis of the material leaked online by the attackers. The package leaked online include also a number of exploits used by the company to compromise targeted systems by exploiting flaws in Adobe Flash ad Internet Explorer applications.
The researchers discovered at least three different software exploits, two designed to hack Adobe Flash Player and one for Microsoft’s Windows kernel. In particular the “Use-after-free vulnerability”, coded as CVE-2015-0349 has already been patched.
“The information dump includes at least three exploits – two for Flash Player and one for the Windows kernel. One of the Flash Player vulnerabilities, CVE-2015-0349, has already been patched.” states the post published by Trend Micro.
The experts at the Hacking Team described the second Flash Player exploit as “the most beautiful Flash bug for the last four years,” it still has no CVE associated.
“One of the Flash exploits is described by Hacking Team as “the most beautiful Flash bug for the last four years.” This Flash exploit has not yet been given the CVE number.” continues the post.
Another disconcerting discovery made by principal security firms, is the inclusion of the Adobe Flash zero-day (CVE-2015-5119) exploit with several exploit kits available in the criminal underground. The malware researchers at Trend Micro have discovered evidence of the Adobe Flash zero-day (CVE-2015-5119) exploit being used in a number of exploit kits before the vulnerability was publicly revealed in this week’s data breach on the spyware company. To avoid problems, apply urgently the patch provided by Adobe.
The attackers used the Flash zero-day exploits to cause a system crash and take full control of the infected systems. According to the researchers at Trend Micro this particular zero-day exploit was used in cyber attacks on South Korea and Japan.
“In late June, we learned that a user in Korea was the attempted target of various exploits, including CVE-2014-0497, a Flash vulnerability discovered last year. Traffic logs indicate the user may have received spear phishing emails with attached documents. These documents contained a URL for the user to visit; this URL led to a site hosted in the United States which contained a Flash exploit, detected as SWF_EXPLOYT.YYKI. This particular exploit targets the zero-day Adobe vulnerability that was disclosed during the Hacking Team leak. We noticed that this exploit was downloaded to the user’s machine several times in a week.” wrote Trend Micro.
“We also found that other users had also visited the domain that hosted the exploit code. While many of these users were also in Korea, one of them was located in Japan. This activity started as early as June 22. We cannot confirm that they too were the subject of exploit attempts, but this is likely.”
According to the researchers, the zero-day exploit, about which the rest of the world got access on Monday, was apparently used in limited cyber attacks on South Korea and Japan. The researchers confirmed that the zero-day exploit code they analyzed was very similar to the exploit code included in the HAcking Team Package.
This circumstance suggests that the attackers had access to the hacking tools offered by the Hacking Team firm.
“We believe this attack was generated by Hacking Team’s attack package and code.” states Trend Micro.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(Security Affairs – Hacking Team, zero-day)
[adrotate banner=”5″]
[adrotate banner=”13″
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/38469/cyber-crime/hacking-team-zero-day-korea-japan.html