Adobe releases fix for actively exploited Flash Player zero-day
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-5002 | Stack Buffer Overflow RCE in Adobe Flash Player CVE-2018-5002 is a stack-based buffer overflow (out-of-bounds write) in Adobe Flash Player that can lead to remote code execution. It is triggered when the affected Flash Player processes malicious Flash content, typically delivered remotely through a browser or another application that renders SWF content. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Flash Player. Anyone still running affected versions of Adobe Flash Player is affected, though the product is now end-of-life, and CISA's required action is to disconnect or remove it if still in use. The flaw is being exploited in the wild per its inclusion in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), with a 25.4% EPSS probability of exploitation within 30 days (98th percentile); no public PoC is known. Do: Because Flash Player is end-of-life, the recommended action is to fully uninstall Adobe Flash Player from all systems, prioritizing internet-facing and server workstations, and block or disable Flash content in browsers. Where Flash cannot yet be removed, ensure the latest available Flash release with the 2018 vendor fix for this issue is installed and restrict rendering of untrusted SWF content. Hunt for signs of exploitation per the KEV entry, and treat any remaining Flash-enabled endpoint as a legacy-asset risk. | 7.8 | 25% | KEV |
| mass≈ tens of millions of legacy installations worldwide (Flash Player historically shipped on nearly every Windows PC and in major browsers) |
Full article319 words · extracted from helpnetsecurity.com · click to collapse
If you’re still using Flash Player, it’s time to update it again – and quickly: Adobe has just patched a critical zero day vulnerability (CVE-2018-5002) actively exploited in the wild.
The attacks are “limited, targeted attacks against Windows users,” but updates (v30.0.0.113 for all platforms) are available for Adobe Flash Player for Windows, macOS, Linux and Chrome OS.

About CVE-2018-5002 and the attacks
It is a stack-based buffer overflow vulnerability that has been independently discovered by Qihoo 360, ICEBRG and Tencent researchers.
This attack mainly targets the Middle East, Qihoo 360 researchers noted. The file that delivers the exploit is named ***salary.xls. The file’s content is consistent with the title, is in Arabic (it is believed that the targets are in Qatar) and shows salaries for various time periods.
“The attack loads Adobe Flash Player from within Microsoft Office, which is a popular approach to Flash exploitation since Flash is disabled in many browsers. Attackers typically embed a Flash file within a document, which may contain the entire exploit, or may stage the attack to download exploits and payloads more selectively (e.g. APT28/Sofacy DealersChoice). This leaves, at a minimum, a small Flash loader that defenders can flag for detection and analysts can fingerprint for tracking,” ICEBRG researchers explained.
“Contrary to typical tactics, this attack uses a lesser-known feature that remotely includes the Flash content instead of directly embedding it within the document”.
Once the document was opened, the exploit code and malicious payload were delivered from remote servers.
Flash Player updates
The Flash Player updates contain also fixes for three additional flaws, one of which can also lead to arbitrary code execution.
Users who have selected the option to “Allow Adobe to install updates” will receive the update automatically. Users who haven’t done that can install the update via the update mechanism within the product. Another option is to remove Flash Player altogether from their machines.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2018/06/08/cve-2018-5002/