Adobe releases emergency fix for Flash Player zero-day exploited in the wild
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-11292 | Type Confusion in Adobe Flash Player 27 Allows Arbitrary Code Execution Adobe Flash Player 27.0.0.159 and earlier contains a flawed bytecode verification procedure (CWE-843, type confusion) that lets an untrusted value be used to compute an array index, corrupting object types in the Flash runtime. The flaw is triggered when a user views attacker-crafted Flash (SWF) content — for example embedded in a malicious document or webpage — since the attack vector is network-based with user interaction required and no privileges needed. Successful exploitation yields arbitrary code execution in the context of the Flash process, typically giving the attacker code execution on the endpoint with the current user's rights. Anyone still running Flash Player 27.0.0.159 or earlier is affected, including the Desktop Runtime and the Flash plugin bundled in Red Hat Enterprise Linux Desktop, Server, and Workstation environments; the product has since reached end-of-life. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-03 (ransomware use unknown), related headlines tie it to the October 2017 BlackOasis APT zero-day attacks, and EPSS assigns an ~12% probability of exploitation in the next 30 days (96th percentile). Do: Uninstall or disconnect Adobe Flash Player everywhere it is still present — the product is end-of-life and CISA's required action is to disconnect impacted systems still in use. If Flash must temporarily remain (e.g., Red Hat Enterprise Linux systems using the supplementary Flash plugin or legacy desktops), ensure it runs a release later than 27.0.0.159 and block SWF content in browsers, email, and Office documents. Hunt for residual Flash installs, browser plugins, and embedded .swf content before decommissioning. | 8.8 | 12% | KEV |
| mass~1 billion active Flash users at the time of disclosure; today only residual legacy installs remain, plausibly hundreds of thousands to millions of systems | |
| CVE-2017-8759 | Remote Code Execution in Microsoft .NET Framework via Malicious Documents (CWE-94) CVE-2017-8759 is a code injection flaw (CWE-94) in Microsoft .NET Framework's handling of SOAP WSDL parsing, in which untrusted content referenced by a document or application is parsed and used during object instantiation, allowing attacker-controlled code to run. An attacker triggers it by delivering a specially crafted document — notably a Microsoft Word file referencing a malicious WSDL URL — and gets code execution when the document is opened and .NET downloads and parses the referenced content. Successful exploitation gives the attacker code execution with the privileges of the current user, sufficient to install malware, steal data, or facilitate further compromise. Any Windows system running .NET Framework versions 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, or 4.7 is affected, which at disclosure covered the vast majority of Windows desktops and servers in use. The flaw was a zero-day exploited in the wild at disclosure (September 2017, used in targeted attacks including BlackOasis), is listed in CISA's Known Exploited Vulnerabilities catalog, and public proof-of-concept exploits are available. Do: Apply Microsoft's security updates addressing this vulnerability to all affected .NET Framework versions on Windows endpoints and servers, per the CISA KEV required action. Prioritize user-facing systems that open documents and are internet-exposed, and verify installed .NET Framework versions before and after remediation. As a compensating control, exercise caution with untrusted documents and block or inspect outbound fetches of WSDL references embedded in Office files. | 7.8 | 89% | KEV PoC ×2 |
| masshundreds of millions of Windows devices (affected .NET Framework versions were enabled by default across broadly deployed Windows client and server releases) |
Full article454 words · extracted from helpnetsecurity.com · click to collapse
Adobe has released an out-of-band security update for Adobe Flash Player that patches a zero-day remote code execution vulnerability actively exploited in the wild.

Kaspersky Lab researchers spotted the live attacks on October 10, 2017, and say that the exploit is delivered through a Microsoft Word document and deploys the most recent version of the FinSpy (aka FinFisher) commercial malware developed by Gamma International.
The attack leveraging CVE-2017-11292
The researchers believe that the zero-day is being leveraged by a threat actor known as BlackOasis, who they also credit for exploiting CVE-2017-8759, another zero day used for distributing FinSpy that has been reported in September.
“The FinSpy payload used in the current attacks (CVE-2017-11292) shares the same command and control server as the payload used with CVE-2017-8759 uncovered by FireEye,” they noted.
Once CVE-2017-11292 is exploited, the FinSpy malware is installed on the target computer and connects to C&C servers located in Switzerland, Bulgaria and the Netherlands, to await further instructions and exfiltrate data. At the same time, a lure/decoy document is displayed to the victim.
The researchers believe these attacks are minimal and highly targeted, as they flagged only one in their customer base.
BlackOasis has a long history of exploiting zero-days in their attacks – they used at least five since June 2015. Their interests span a wide gamut of figures involved in Middle Eastern politics and verticals disproportionately relevant to the region, the researchers noted. This includes prominent figures in the United Nations, opposition bloggers and activists, and regional news correspondents.
“The attack using the recently discovered zero-day exploit is the third time this year we have seen FinSpy distribution through exploits to zero-day vulnerabilities,” said Anton Ivanov, lead malware analyst at Kaspersky Lab. “Previously, actors deploying this malware abused critical issues in Microsoft Word and Adobe products. We believe the number of attacks relying on FinSpy software, supported by zero day exploits such as the one described here, will continue to grow.”
Protection
According to the security bulletin released by Adobe, the vulnerability is currently being exploited in attacks against users running Windows, but affected product versions also include:
- Adobe Flash Player Desktop Runtime for Macintosh and Linux
- Adobe Flash Player for Microsoft Edge and Internet Explorer 11 (Windows 10 and 8.1)
- Adobe Flash Player for Google Chrome (on Windows, Macintosh, Linux and Chrome OS).
All these product versions should be upgraded as soon as possible to version 27.0.0.170, as there can be no doubt that this exploit will soon trickle down to and be used by regular cyber criminals, against a wide array of targets.
Unfortunately, Flash Player tops the list of most outdated programs on users’ PCs.
Users who can do without Flash Player could uninstall it altogether.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2017/10/17/emergency-fix-flash-player-zero-day/