ZeroHour
Security Affairspublished ()ingested @securityaffairs

BlackOasis APT leverages new Flash zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2015-5119
Use-After-Free RCE in Adobe Flash Player (ActionScript 3 ByteArray)

CVE-2015-5119 is a use-after-free memory-corruption vulnerability (CWE-119) in the ActionScript 3 ByteArray class of Adobe Flash Player. It is triggered when Flash processes crafted ActionScript/SWF content — typically a malicious .swf loaded from a web page, advertisement, email attachment, or document — causing Flash to access already-freed memory in an attacker-controllable way. A successful attack gives the adversary remote code execution in the context of the user running Flash. Anyone with Adobe Flash Player installed was exposed; at disclosure Flash was on the vast majority of internet-connected desktops, and today risk is concentrated in legacy browsers, office/document tooling, industrial or enterprise applications, and other systems where Flash was never removed. Exploitation status: this flaw has long-standing in-the-wild use (related headlines tie the leaked Hacking Team Flash exploit to APT campaigns against Japanese, East Asian, and US Government targets and to top 2016 exploit kits), it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03; ransomware use unknown), and EPSS assigns a 99.3% probability of exploitation within 30 days.

Do: Because Flash Player is end-of-life, CISA's required action is to disconnect it rather than patch: audit browsers, document/office tooling, and legacy or industrial applications for Flash dependencies and fully uninstall or disable Flash and any embedded SWF players. If a system must keep Flash temporarily, verify it runs a patched build from 2015 or later (Adobe's July 2015 emergency update, APSB15-16, addressed this flaw) and block untrusted SWF content via browser settings, email gateway, and web filtering. Prioritize cleanup on internet-facing endpoints and users who browse the web or open untrusted email attachments, the typical delivery route for this exploit.

99% KEV
  • Adobe Flash Player
mass≈ millions of legacy desktop installations
CVE-2016-0984
Use-After-Free RCE in Adobe Flash Player and AIR

Adobe Flash Player and Adobe AIR contain a use-after-free memory corruption flaw (CWE-416) that allows remote attackers to execute arbitrary code by persuading a user to load specially crafted Flash content, as the CVSS vector (AV:N/UI:R) indicates exploitation via user interaction such as opening a malicious SWF in a browser or an application embedding Flash/AIR. Successful exploitation gives the attacker code execution with the victim user's privileges, with high impact on confidentiality, integrity, and availability. All Flash Player versions before 18.0.0.329, 19.x/20.x before 20.0.0.306 on Windows and OS X, and before 11.2.202.569 on Linux are affected, along with Adobe AIR Desktop Runtime, AIR SDK, and AIR SDK & Compiler before 20.0.0.260. The flaw was fixed in February 2016 as one of several sibling use-after-free bugs (CVE-2016-0973, -0974, -0975, -0982, -0983), and a public proof of concept is available (Exploit-DB 39462). CISA added it to the Known Exploited Vulnerabilities catalog on 2022-05-25, confirming known in-the-wild exploitation (ransomware use unknown), and EPSS at 54.8% (99th percentile) indicates continued likelihood of exploitation against remaining exposed systems.

Do: Upgrade Flash Player to 18.0.0.329, or 20.0.0.306 on Windows/macOS and 11.2.202.569 on Linux, and upgrade AIR, AIR SDK, and AIR SDK & Compiler to 20.0.0.260. Because Flash is end-of-life, per CISA KEV guidance the preferred action is to remove or disable Flash entirely and disconnect any system still running it; audit legacy browsers, kiosks, industrial HMIs, and embedded apps that still load SWF content, since exploitation requires user-opened Flash content.

8.855% KEV PoC
  • Adobe Flash Player All versions before 18.0.0.329; 19.x and 20.x before 20.0.0.306 on Windows and OS X; before 11.2.202.569 on Linux
  • Adobe Flash Player Desktop Runtime All versions before 18.0.0.329; 19.x and 20.x before 20.0.0.306 on Windows and OS X; before 11.2.202.569 on Linux
  • Adobe AIR Desktop Runtime Before 20.0.0.260
  • +2 more
massApproximately 1 billion+ installations at the time of disclosure (Flash was installed on the vast majority of internet-connected PCs in early 2016); current…
CVE-2016-4117
Arbitrary Code Execution in Adobe Flash Player 21.0.0.226 and earlier

CVE-2016-4117 is a critical (CVSS 3.1: 9.8) arbitrary code execution vulnerability in Adobe Flash Player 21.0.0.226 and earlier, in which unspecified vectors in the Flash runtime allow remote attackers to execute arbitrary code. It is triggered by delivering malicious Flash content over a network — for example a crafted SWF loaded by a browser or an application that embeds Flash — and, per its CVSS scoring, requires no privileges or authentication. A successful exploit gives the attacker code execution in the context of the Flash runtime (typically the user's browser process), which public reporting shows was used to deliver espionage tooling and, per CISA, is also known to be used in ransomware campaigns. Anyone running Flash Player 21.0.0.226 or earlier was affected, including users of the flash-player packages shipped for Red Hat Enterprise Linux Desktop, Server (including the RHUI variant) and Workstation, openSUSE, openSUSE Evergreen, and SUSE Linux Enterprise Desktop and the SUSE Linux Enterprise Workstation Extension. The bug was exploited in the wild in May 2016 — related headlines tie it to the BlackOasis APT 'Operation Daybreak' espionage campaign using FinFisher — and it was added to the CISA KEV on 2022-03-03 with known ransomware use and a very high 94.4% EPSS.

Do: Per CISA's required action, Flash Player is end-of-life: remove or disable Flash wherever it is still present and uninstall the flash-player packages on any remaining RHEL, SUSE or openSUSE hosts, especially internet-facing systems. If a legacy system must keep Flash, ensure it runs a release later than 21.0.0.226 (a fixed build from the May 2016 Adobe update or later) and restrict it from untrusted web content.

9.894% KEV ransomware PoC
  • adobe Flash Player 21.0.0.226 and earlier (all editions)
  • redhat Enterprise Linux Desktop (flash-player package)
  • redhat Enterprise Linux Server (flash-player package)
  • +6 more
mass≈100M+ desktop users at the time of disclosure (Flash was then near-universal); residual small base of end-of-life installs today
CVE-2017-11292
Type Confusion in Adobe Flash Player 27 Allows Arbitrary Code Execution

Adobe Flash Player 27.0.0.159 and earlier contains a flawed bytecode verification procedure (CWE-843, type confusion) that lets an untrusted value be used to compute an array index, corrupting object types in the Flash runtime. The flaw is triggered when a user views attacker-crafted Flash (SWF) content — for example embedded in a malicious document or webpage — since the attack vector is network-based with user interaction required and no privileges needed. Successful exploitation yields arbitrary code execution in the context of the Flash process, typically giving the attacker code execution on the endpoint with the current user's rights. Anyone still running Flash Player 27.0.0.159 or earlier is affected, including the Desktop Runtime and the Flash plugin bundled in Red Hat Enterprise Linux Desktop, Server, and Workstation environments; the product has since reached end-of-life. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-03 (ransomware use unknown), related headlines tie it to the October 2017 BlackOasis APT zero-day attacks, and EPSS assigns an ~12% probability of exploitation in the next 30 days (96th percentile).

Do: Uninstall or disconnect Adobe Flash Player everywhere it is still present — the product is end-of-life and CISA's required action is to disconnect impacted systems still in use. If Flash must temporarily remain (e.g., Red Hat Enterprise Linux systems using the supplementary Flash plugin or legacy desktops), ensure it runs a release later than 27.0.0.159 and block SWF content in browsers, email, and Office documents. Hunt for residual Flash installs, browser plugins, and embedded .swf content before decommissioning.

8.812% KEV
  • Adobe Flash Player Desktop Runtime 27.0.0.159 and earlier
  • Adobe Flash Player (browser/runtime variants) 27.0.0.159 and earlier
  • Red Hat Enterprise Linux Desktop (with Flash Player plugin) Flash Player 27.0.0.159 and earlier (RHEL release not specified in source data)
  • +2 more
mass~1 billion active Flash users at the time of disclosure; today only residual legacy installs remain, plausibly hundreds of thousands to millions of systems
CVE-2017-8759
Remote Code Execution in Microsoft .NET Framework via Malicious Documents (CWE-94)

CVE-2017-8759 is a code injection flaw (CWE-94) in Microsoft .NET Framework's handling of SOAP WSDL parsing, in which untrusted content referenced by a document or application is parsed and used during object instantiation, allowing attacker-controlled code to run. An attacker triggers it by delivering a specially crafted document — notably a Microsoft Word file referencing a malicious WSDL URL — and gets code execution when the document is opened and .NET downloads and parses the referenced content. Successful exploitation gives the attacker code execution with the privileges of the current user, sufficient to install malware, steal data, or facilitate further compromise. Any Windows system running .NET Framework versions 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, or 4.7 is affected, which at disclosure covered the vast majority of Windows desktops and servers in use. The flaw was a zero-day exploited in the wild at disclosure (September 2017, used in targeted attacks including BlackOasis), is listed in CISA's Known Exploited Vulnerabilities catalog, and public proof-of-concept exploits are available.

Do: Apply Microsoft's security updates addressing this vulnerability to all affected .NET Framework versions on Windows endpoints and servers, per the CISA KEV required action. Prioritize user-facing systems that open documents and are internet-exposed, and verify installed .NET Framework versions before and after remediation. As a compensating control, exercise caution with untrusted documents and block or inspect outbound fetches of WSDL references embedded in Office files.

7.889% KEV PoC ×2
  • microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7
masshundreds of millions of Windows devices (affected .NET Framework versions were enabled by default across broadly deployed Windows client and server releases)

Indicators of compromiseAll →

TypeIndicatorContext
ipv421.0.0.226critical type confusion vulnerability affects Flash Player 21.0.0.226 for Windows, Macintosh, Linux and Chrome OS. “On October 10
ipv427.0.0.159ddressed it with the release of Adobe Flash Player versions 27.0.0.159 and 27.0.0.130.
Full article589 words · extracted from securityaffairs.com · click to collapse

Security researchers from Kaspersky Labs spotted the BlackOasis APT group exploiting a new zero-day RCE vulnerability in Adobe Flash.

Security researchers from Kaspersky Labs have discovered a new zero-day remote code execution vulnerability in Adobe Flash, tracked as CVE-2017-11292, which was being actively exploited by hackers in the wild to deliver the surveillance software FinSpy.

BlackOasis APT

Hackers belonging to the APT group known as BlackOasis are leveraging the Adobe Flash zero-day exploit in attacks against high-profile targets.

The critical type confusion vulnerability affects Flash Player 21.0.0.226 for Windows, Macintosh, Linux and Chrome OS.

“On October 10, 2017, Kaspersky Lab’s advanced exploit prevention systems identified a new Adobe Flash zero day exploit used in the wild against our customers. The exploit was delivered through a Microsoft Office document and the final payload was the latest version of FinSpy malware. We have reported the bug to Adobe who assigned it CVE-2017-11292 and released a patch earlier today:” reads the analysis published by Kaspersky.

The experts speculate the BlackOasis APT group is the same crew that exploited another RCE zero-day vulnerability, tracked CVE-2017-8759, discovered by FireEye researchers in September 2017.

According to FireEye, the CVE-2017-8759 was actively been exploited by an APT group to deliver the surveillance malware FinFisher Spyware (FinSpy) to a Russian-speaking “entity” via malicious Microsoft Office RTF files in July.

In both attacks, the BlackOasis APT exploited a zero-day exploit to deliver the FinSpy spyware, the hackers shared the same command and control (C&C).

The experts who monitored the activity of the BlackOasis group across the year confirmed it has utilized at least five zero days since June 2015:

BlackOasis hackers targeted individuals in numerous countries, including Russia, Iraq, Afghanistan, Nigeria, Libya, Jordan, Tunisia, Saudi Arabia, Iran, the Netherlands, Bahrain, United Kingdom and Angola.

“BlackOasis’ interests span a wide gamut of figures involved in Middle Eastern politics and verticals disproportionately relevant to the region. This includes prominent figures in the United Nations, opposition bloggers and activists, and regional news correspondents.” continues the analysis. “During 2016, we observed a heavy interest in Angola, exemplified by lure documents indicating targets with suspected ties to oil, money laundering, and other illicit activities. There is also an interest in international activists and think tanks.”

Researchers reported the zero-day exploit is delivered through Microsoft Office documents, particularly Word, attached to a spam email. The documents include an ActiveX object which contains the Flash exploit used to deliver the FinSpy spyware.

“The Flash object contains an ActionScript which is responsible for extracting the exploit using a custom packer seen in other FinSpy exploits,” the Kaspersky Labs researchers say.

FinSpy leveraged various attack vectors, including spear phishing, manual installation with physical access to the affected device, zero-day exploits, and watering hole attacks.

According to the experts, the number of attacks relying on FinFisher software, supported by zero-day exploits  will continue to grow.

“The attack using the recently discovered zero-day exploit is the third time this year we have seen FinSpy distribution through exploits to zero-day vulnerabilities,” conclude Kaspersky Lab lead malware analyst Anton Ivanov

“Previously, actors deploying this malware abused critical issues in Microsoft Word and Adobe products. We believe the number of attacks relying on FinSpy software, supported by zero day exploits such as the one described here, will continue to grow.”

Kaspersky Lab reported the flaw to Adobe that addressed it with the release of Adobe Flash Player versions 27.0.0.159 and 27.0.0.130.



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/64383/apt/blackoasis-apt-finspy.html