ZeroHour
Security Affairspublished ()ingested @securityaffairs

Adobe fixed the CVE-2018-5002 Flash Zero-Day exploited in targeted attacks in the Middle East

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-4878
Use-After-Free RCE in Adobe Flash Player before 28.0.0.161

CVE-2018-4878 is a use-after-free (CWE-416) in Adobe Flash Player before 28.0.0.161, caused by a dangling pointer in the Primetime SDK's media-player handling of listener objects. An attacker triggers it by persuading a user to open attacker-controlled Flash content — typically a malicious SWF delivered via email, Office documents, or malvertising/exploit kits — because the CVSS vector (AV:L, UI:R) requires local user interaction. Successful exploitation yields arbitrary code execution with the privileges of the user running Flash. Anyone running a vulnerable Flash Player was exposed, including Red Hat Enterprise Linux Desktop/Server/Workstation users running Red Hat's packaged Flash plugin. The flaw was exploited as a zero-day in January–February 2018 (documented by McAfee and distributed alongside the Fallout exploit kit), and it remains in CISA's KEV with known ransomware use.

Do: Upgrade Adobe Flash Player to 28.0.0.161 or later, including Red Hat's flash-plugin package on RHEL Desktop/Server/Workstation. Because Flash is now end-of-life, CISA's required KEV action is to remove or disconnect Flash entirely where still in use — audit browsers, Office configurations, and legacy RHEL hosts for residual Flash installs, and block SWF content delivered via email and the web. Given confirmed in-the-wild exploitation, known ransomware use, and 89.5% EPSS, prioritize this in remediation tracking.

7.890% KEV ransomware PoC ×2
  • adobe Flash Player all versions before 28.0.0.161
  • redhat Enterprise Linux Desktop (flash-plugin) Flash Player component before 28.0.0.161
  • redhat Enterprise Linux Server (flash-plugin) Flash Player component before 28.0.0.161
  • +1 more
mass≈ hundreds of millions of desktop installs at time of disclosure; residual unmigrated installs now unknown (Flash is end-of-life)
CVE-2018-4945
+2 in the same advisory: …5000 …5001
Adobe Flash Player versions 29.0.0.171 and earlier have a Type Confusion vulnerability.

Adobe Flash Player versions 29.0.0.171 and earlier have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

NVD description · AI analysis pending
8.8
group max
7%
  • adobe flash player desktop runtime
  • adobe flash player
  • adobe enterprise linux desktop
  • +1 more
CVE-2018-5002
Stack Buffer Overflow RCE in Adobe Flash Player

CVE-2018-5002 is a stack-based buffer overflow (out-of-bounds write) in Adobe Flash Player that can lead to remote code execution. It is triggered when the affected Flash Player processes malicious Flash content, typically delivered remotely through a browser or another application that renders SWF content. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Flash Player. Anyone still running affected versions of Adobe Flash Player is affected, though the product is now end-of-life, and CISA's required action is to disconnect or remove it if still in use. The flaw is being exploited in the wild per its inclusion in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), with a 25.4% EPSS probability of exploitation within 30 days (98th percentile); no public PoC is known.

Do: Because Flash Player is end-of-life, the recommended action is to fully uninstall Adobe Flash Player from all systems, prioritizing internet-facing and server workstations, and block or disable Flash content in browsers. Where Flash cannot yet be removed, ensure the latest available Flash release with the 2018 vendor fix for this issue is installed and restrict rendering of untrusted SWF content. Hunt for signs of exploitation per the KEV entry, and treat any remaining Flash-enabled endpoint as a legacy-asset risk.

7.825% KEV
  • Adobe Flash Player All versions released prior to the vendor's 2018 security update addressing this flaw; the product is now end-of-life (no patched release line is maintained)
mass≈ tens of millions of legacy installations worldwide (Flash Player historically shipped on nearly every Windows PC and in major browsers)

Indicators of compromiseAll →

TypeIndicatorContext
ipv429.0.0.171ates address critical vulnerabilities in Adobe Flash Player 29.0.0.171 and earlier versions. Successful exploitation could lead to
ipv430.0.0.113reads the analysis published by Qihoo 360. The Flash Player 30.0.0.113 version also addresses the following vulnerabilities: CVE-2
Full article521 words · extracted from securityaffairs.com · click to collapse

Adobe has recently fixed several vulnerabilities, including the CVE-2018-5002 Flash Zero-Day exploited in targeted attacks in the Middle East

Adobe has released security updates for Flash Player that address four vulnerabilities, including a critical issue (CVE-2018-5002) that has been exploited in targeted attacks mainly aimed at entities in the Middle East.

The CVE-2018-5002 vulnerability, reported by researchers at ICEBRG and Qihoo 360 and Tencent,  is a stack-based buffer overflow that can be exploited by attackers arbitrary code execution.

“Adobe has released security updates for Adobe Flash Player for Windows, macOS, Linux and Chrome OS. These updates address critical vulnerabilities in Adobe Flash Player 29.0.0.171 and earlier versions.  Successful exploitation could lead to arbitrary code execution in the context of the current user.” reads the security advisory published by Adobe.

“Adobe is aware of a report that an exploit for CVE-2018-5002 exists in the wild, and is being used in limited, targeted attacks against Windows users. These attacks leverage Office documents with embedded malicious Flash Player content distributed via email.”

The researcher did not disclose technical details of the vulnerability, but Adobe confirmed that the zero-day was exploited in targeted attacks against Windows users.

Attackers launched spear phishing attacks using messages with weaponized Office documents (Excel spreadsheet named “salary.xlsx) that contain specially crafted Flash content.

“The hackers carefully constructed an Office document that remotely loaded Flash vulnerability. When the document was opened, all the exploit code and malicious payload were delivered through remote servers. This attack mainly targets the Middle East.” reads the analysis published by Qihoo 360.

The Flash Player 30.0.0.113 version also addresses the following vulnerabilities:

  • CVE-2018-4945 –  a critical type confusion vulnerability that can lead to code execution, it was reported by researchers at Tencent.
  • CVE-2018-5000 – an “important” severity integer overflow that can lead to information disclosure,  it was reported anonymously through Trend Micro’s Zero Day Initiative (ZDI).
  • CVE-2018-5001 – an “important” out-of-bounds read flaw that can lead to information disclosure, it was reported anonymously through Trend Micro’s Zero Day Initiative (ZDI).

This is the second zero-day discovered in 2018, the first Adobe zero-day, tracked as CVE-2018-4878, was patched in February after it was exploited by North Korea-linked nation-state hackers in attacks aimed at South Korea. The flaw was later exploited by different cybercrime gangs.

According to the analysis published by Qihoo 360, attackers were preparing the campaign recently detected at least since February. The C&C domain appears as a job search website in the Middle East and its name leads the experts into believing that the target is located in Doha, Qatar.

“Through analysis, we can see that the attack used a 0-day vulnerability regardless of the cost. The attacker developed sophisticated plans in the cloud and spent at least three months preparing for the attack. The detailed phishing attack content was also tailored to the attack target. All clues show this is a typical APT attack. We suggest all relevant organizations and users to update their Flash to the latest versions in a timely manner. ” concludes Qihoo 360.

[adrotate banner=”9″] [adrotate banner=”12″]  

Pierluigi Paganini

(Security Affairs – Adobe, CVE-2018-5002)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/73291/hacking/cve-2018-5002-zero-day.html