ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

About the Flash zero-day currently exploited in the wild

criticalExploit / PoC exploited in the wildimportance 60CVE-2018-4878

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-4878
Use-After-Free RCE in Adobe Flash Player before 28.0.0.161

CVE-2018-4878 is a use-after-free (CWE-416) in Adobe Flash Player before 28.0.0.161, caused by a dangling pointer in the Primetime SDK's media-player handling of listener objects. An attacker triggers it by persuading a user to open attacker-controlled Flash content — typically a malicious SWF delivered via email, Office documents, or malvertising/exploit kits — because the CVSS vector (AV:L, UI:R) requires local user interaction. Successful exploitation yields arbitrary code execution with the privileges of the user running Flash. Anyone running a vulnerable Flash Player was exposed, including Red Hat Enterprise Linux Desktop/Server/Workstation users running Red Hat's packaged Flash plugin. The flaw was exploited as a zero-day in January–February 2018 (documented by McAfee and distributed alongside the Fallout exploit kit), and it remains in CISA's KEV with known ransomware use.

Do: Upgrade Adobe Flash Player to 28.0.0.161 or later, including Red Hat's flash-plugin package on RHEL Desktop/Server/Workstation. Because Flash is now end-of-life, CISA's required KEV action is to remove or disconnect Flash entirely where still in use — audit browsers, Office configurations, and legacy RHEL hosts for residual Flash installs, and block SWF content delivered via email and the web. Given confirmed in-the-wild exploitation, known ransomware use, and 89.5% EPSS, prioritize this in remediation tracking.

7.890% KEV ransomware PoC ×2
  • adobe Flash Player all versions before 28.0.0.161
  • redhat Enterprise Linux Desktop (flash-plugin) Flash Player component before 28.0.0.161
  • redhat Enterprise Linux Server (flash-plugin) Flash Player component before 28.0.0.161
  • +1 more
mass≈ hundreds of millions of desktop installs at time of disclosure; residual unmigrated installs now unknown (Flash is end-of-life)

Indicators of compromiseAll →

TypeIndicatorContext
ipv428.0.0.137t could lead to remote code execution in Adobe Flash Player 28.0.0.137 and earlier versions.
Full article539 words · extracted from helpnetsecurity.com · click to collapse

The zero-day Flash Player vulnerability (CVE-2018-4878) that Adobe warned about on Thursday was leveraged by North Korean hackers.

Flash zero-day

FireEye calls the group TEMP.Reaper and Cisco researchers named it Group 123 (and have been tracking their exploits for a while).

The threat actors leveraging the Flash zero-day

“We have observed TEMP.Reaper operators directly interacting with their command and control infrastructure from IP addresses assigned to the STAR-KP network in Pyongyang. The STAR-KP network is operated as a joint venture between the North Korean Government’s Post and Telecommunications Corporation and Thailand-based Loxley Pacific,” FireEye researchers noted.

“Historically, the majority of their targeting has been focused on the South Korean government, military, and defense industrial base; however, they have expanded to other international targets in the last year.”

In this latest attack, first flagged by the South Korean CERT, the targets were obviously South Korean.

The Excel file carrying an embedded SWF file with the exploit is in Korean.

“Upon opening and successful exploitation, a decryption key for an encrypted embedded payload would be downloaded from compromised third-party websites hosted in South Korea. Preliminary analysis indicates that the vulnerability was likely used to distribute the previously observed DOGCALL malware to South Korean victims,” FireEye researchers shared.

Cisco researchers call the malware ROKRAT, and it allows attackers to fiddle with the compromised system remotely.

“One of the ROKRAT samples identified used a naming reference to Hancom Secure AnySign. It is a reference to a legitimate application developed by Hancom Secure for PKI & authentication mechanisms. It is a software application used to protect user data and is massively used in South Korea,” they explained.

“This payload is a shellcode loaded in memory and executed. We identified Flash exploits from November 2017.”

Mitigation and fixes

This was apparently an extremely targeted attack, and it is unlikely that anyone else is taking advantage of the exploit – for now. Still, with the vulnerability now public, it’s likely that criminals are already working on creating an exploit.

Adobe has said it “will address this vulnerability in a release planned for the week of February 5.”

In the meantime, they advised enterprise administrators to consider implementing Protected View for Office, so potentially unsafe files are opened in Read-only mode.

End users could temporarily uninstall Flash if they don’t particularly need it.

“The most common ‘need’ we hear for Flash is to watch web videos, but almost all websites will use HTML5 for videos if you don’t have Flash. If you uninstall it, your browser will use its built-in video player instead – so you probably don’t need Flash after all,” Sophos’ Paul Ducklin noted.

He also pointed out that just turning off Flash in your browser isn’t enough to remove the risk of this particular attack – the Flash Player software has to be removed from the computer as a whole.

If you choose to continue using Flash Player, implement the security updates when they are released or as soon as possible.

UPDATE (February 6, 2018):

Adobe has released security updates for Adobe Flash Player for Windows, Macintosh, Linux and Chrome OS, to fix CVE-2018-4878 and another critical vulnerability that could lead to remote code execution in Adobe Flash Player 28.0.0.137 and earlier versions.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2018/02/05/flash-zero-day-currently-exploited-wild/