ZeroHour
Security Affairspublished ()ingested @securityaffairs

APT28 group is rushing to exploit recent CVE-2017-11292 Flash 0

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2015-7645
Arbitrary Code Execution in Adobe Flash Player via Crafted SWF Files

CVE-2015-7645 is a code execution vulnerability in Adobe Flash Player in which a remote attacker can execute arbitrary code by having the player process a maliciously crafted SWF (Flash) file. Triggering requires only that a user load attacker-supplied Flash content, for example by visiting a compromised or malicious website, opening a document that embeds Flash content, or receiving an SWF payload delivered through an exploit kit. Successful exploitation lets the attacker run arbitrary code in the context of the Flash process, typically enabling malware or ransomware installation and compromise of the user's account and data. Anyone running Adobe Flash Player when the flaw was disclosed in 2015 was affected, and because Flash has since reached end-of-life, any installations that remain in use are unpatched. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03) with known ransomware use, and its EPSS score of 65.6% (99th percentile) indicates a high probability of exploitation.

Do: Remove or disable Adobe Flash Player entirely, consistent with CISA's required action, which notes the product is end-of-life and should be disconnected if still in use; audit for legacy Flash instances in intranet applications, bundled enterprise software, and older browser configurations. If Flash cannot be removed, install the latest patched release available from Adobe for this vulnerability and ensure browsers block or sandbox SWF content. Given the confirmed ransomware use, prioritize hunting for exploitation on any systems where Flash remains installed.

66% KEV ransomware
  • Adobe Flash Player
mass≈1 billion+ users/devices at the time of disclosure (Flash then ran on nearly all desktops); the number of leftover unpatched installs today is unknown
CVE-2016-1019
Arbitrary code execution flaw in Adobe Flash Player, used in ransomware attacks

CVE-2016-1019 is a remotely exploitable flaw in Adobe Flash Player that lets an attacker cause a denial of service or, in the worst case, execute arbitrary code on the victim's system. It is triggered remotely, typically when a user views malicious Flash content delivered through a web browser, an application, or a document that embeds Flash content. A successful attack runs code with the privileges of the logged-on user, making the bug a useful foothold for deploying malware, including ransomware. Anyone still running Adobe Flash Player is potentially affected - the product is end-of-life (support ended December 31, 2020), but it persists on legacy desktops, intranet applications, kiosks, and embedded or industrial systems; the CISA data does not list specific affected version ranges. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on March 3, 2022, notes known ransomware use, and EPSS assigns a 22.5% probability of exploitation in the next 30 days (98th percentile), though no public proof-of-concept is catalogued.

Do: Per CISA's required action, disconnect or remove any system still running Adobe Flash Player, since the product is end-of-life and receives no further security updates; the bug was patched in Adobe's 2016 updates, so only long-unupdated or embedded Flash installs remain vulnerable. Uninstall Flash from browsers and legacy software and confirm that no internal applications or sites still serve or require SWF content. Because exploitation is tied to ransomware campaigns, prioritize user workstations and any internet-facing host with Flash installed.

9.822% KEV ransomware
  • Adobe Flash Player
mass≈ millions of legacy endpoints worldwide (Flash historically ran on ~99% of internet-connected PCs; current residual install count unknown)
CVE-2016-4117
Arbitrary Code Execution in Adobe Flash Player 21.0.0.226 and earlier

CVE-2016-4117 is a critical (CVSS 3.1: 9.8) arbitrary code execution vulnerability in Adobe Flash Player 21.0.0.226 and earlier, in which unspecified vectors in the Flash runtime allow remote attackers to execute arbitrary code. It is triggered by delivering malicious Flash content over a network — for example a crafted SWF loaded by a browser or an application that embeds Flash — and, per its CVSS scoring, requires no privileges or authentication. A successful exploit gives the attacker code execution in the context of the Flash runtime (typically the user's browser process), which public reporting shows was used to deliver espionage tooling and, per CISA, is also known to be used in ransomware campaigns. Anyone running Flash Player 21.0.0.226 or earlier was affected, including users of the flash-player packages shipped for Red Hat Enterprise Linux Desktop, Server (including the RHUI variant) and Workstation, openSUSE, openSUSE Evergreen, and SUSE Linux Enterprise Desktop and the SUSE Linux Enterprise Workstation Extension. The bug was exploited in the wild in May 2016 — related headlines tie it to the BlackOasis APT 'Operation Daybreak' espionage campaign using FinFisher — and it was added to the CISA KEV on 2022-03-03 with known ransomware use and a very high 94.4% EPSS.

Do: Per CISA's required action, Flash Player is end-of-life: remove or disable Flash wherever it is still present and uninstall the flash-player packages on any remaining RHEL, SUSE or openSUSE hosts, especially internet-facing systems. If a legacy system must keep Flash, ensure it runs a release later than 21.0.0.226 (a fixed build from the May 2016 Adobe update or later) and restrict it from untrusted web content.

9.894% KEV ransomware PoC
  • adobe Flash Player 21.0.0.226 and earlier (all editions)
  • redhat Enterprise Linux Desktop (flash-player package)
  • redhat Enterprise Linux Server (flash-player package)
  • +6 more
mass≈100M+ desktop users at the time of disclosure (Flash was then near-universal); residual small base of end-of-life installs today
CVE-2016-7855
Use-After-Free RCE in Adobe Flash Player (Windows, macOS, Linux)

Adobe Flash Player for Windows, macOS/OS X, and Linux contains a use-after-free memory flaw (CWE-416) in which memory that has been freed is referenced again, corrupting memory when the player processes attacker-controlled Flash content remotely, typically via a malicious SWF delivered through a browser or another host application. A successful attack allows arbitrary code execution with the privileges of the user running Flash, commonly leading to full workstation compromise in browsing contexts. Anyone still running an affected Adobe Flash Player build is exposed, although the product has been end-of-life since early 2021 and CISA explicitly advises disconnecting or removing it rather than continuing to patch. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added March 3, 2022), confirming known in-the-wild exploitation, and EPSS assigns a 25.2% probability of exploitation within 30 days (98th percentile); no public proof-of-concept is known and ransomware use is unknown.

Do: Because Flash Player is end-of-life and no longer receives security updates, follow CISA's required action: uninstall or disable Flash everywhere it remains, including browser plugins, standalone installs, and legacy applications that invoke it. If removal must be delayed, ensure the latest patched release from Adobe's security advisories is in place and block or sandbox untrusted Flash content. On systems where Flash is still active, hunt for indicators of compromise given the KEV listing and high EPSS score.

8.825% KEV
  • Adobe Flash Player
mass≈1 billion+ installs historically (Flash was near-ubiquitous; residual post-EOL installs unknown)
CVE-2017-11292
Type Confusion in Adobe Flash Player 27 Allows Arbitrary Code Execution

Adobe Flash Player 27.0.0.159 and earlier contains a flawed bytecode verification procedure (CWE-843, type confusion) that lets an untrusted value be used to compute an array index, corrupting object types in the Flash runtime. The flaw is triggered when a user views attacker-crafted Flash (SWF) content — for example embedded in a malicious document or webpage — since the attack vector is network-based with user interaction required and no privileges needed. Successful exploitation yields arbitrary code execution in the context of the Flash process, typically giving the attacker code execution on the endpoint with the current user's rights. Anyone still running Flash Player 27.0.0.159 or earlier is affected, including the Desktop Runtime and the Flash plugin bundled in Red Hat Enterprise Linux Desktop, Server, and Workstation environments; the product has since reached end-of-life. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-03 (ransomware use unknown), related headlines tie it to the October 2017 BlackOasis APT zero-day attacks, and EPSS assigns an ~12% probability of exploitation in the next 30 days (96th percentile).

Do: Uninstall or disconnect Adobe Flash Player everywhere it is still present — the product is end-of-life and CISA's required action is to disconnect impacted systems still in use. If Flash must temporarily remain (e.g., Red Hat Enterprise Linux systems using the supplementary Flash plugin or legacy desktops), ensure it runs a release later than 27.0.0.159 and block SWF content in browsers, email, and Office documents. Hunt for residual Flash installs, browser plugins, and embedded .swf content before decommissioning.

8.812% KEV
  • Adobe Flash Player Desktop Runtime 27.0.0.159 and earlier
  • Adobe Flash Player (browser/runtime variants) 27.0.0.159 and earlier
  • Red Hat Enterprise Linux Desktop (with Flash Player plugin) Flash Player 27.0.0.159 and earlier (RHEL release not specified in source data)
  • +2 more
mass~1 billion active Flash users at the time of disclosure; today only residual legacy installs remain, plausibly hundreds of thousands to millions of systems
Full article527 words · extracted from securityaffairs.com · click to collapse

The APT28 group is trying to exploit the CVE-2017-11292 Flash zero-day before users receive patches or update their systems.

Security experts at Proofpoint collected evidence of several malware campaigns, powered by the Russian APT28 group, that rely on a Flash zero-day vulnerability that Adobe patched earlier this week.

According to the experts who observed attacks on organizations across Europe and in the US, the APT28 group is trying to exploit the CVE-2017-11292 zero-day before users receive patches or update their systems.

The state-sponsored hackers focused their attacks on state departments and private-sector businesses in the aerospace industry.

“On Tuesday, October 18, Proofpoint researchers detected a malicious Microsoft Word attachment exploiting a recently patched Adobe Flash vulnerability, CVE-2017-11292. We attributed this attack to APT28 (also known as Sofacy), a Russian state-sponsored group.” states the report published by Proofpoint.

“Targeting data for this campaign is limited but some emails were sent to foreign government entities equivalent to the State Department and private-sector businesses in the aerospace industry. The known geographical targeting appears broad, including Europe and the United States. The emails were sent from free email services.”

The patch was released on Monday, October 16, at that time Kaspersky detected attacks leveraging the CVE-2017-11292 allegedly conducted by the BlackOasis APT group.

Researchers believe that APT28 was also in possession of the exploit (whether purchased, discovered on their own, or reverse engineered from the BlackOasis attack), and is trying to use it in targeted attacks.

The APT28 rushed to assemble the exploit and the distribution campaign, reusing code from past attacks, the APT28 hackers did the same in May after Microsoft patched three zero-days flaws exploited by the Russian APT group.

Back to the present, researchers believe the APT28 found a way to exploit the CVE-2017-11292, it is unclear if they purchased the zero-day or reverse engineered it from the BlackOasis attack.

The researchers noticed that the recent attacks exploiting the CVE-2017-11292 flaw employed the same old DealersChoice malware, a Flash exploit framework also used by the APT28 group against Montenegro.

When the target user opens these the weaponized files, DealersChoice contacts the remote server to download the CVE-2017-11292 exploit code and execute it.

“The document “World War 3.docx” contacts DealersChoice.B, APT28’s attack framework that allows loading exploit code on-demand from a command and control (C&C) server. DealersChoice has previously been used to exploit a variety of Flash vulnerabilities, including CVE-2015-7645, CVE-2016-1019, CVE-2016-4117, and CVE-2016-7855 via embedded objects in crafted Microsoft Word documents.” continues the report.

apt28 CVE-2017-11292

The Proofpoint researcher Kafeine, confirmed his company currently trying to take down C&C servers associated with the DealersChoice attack framework used in the CVE-2017-11292 attacks.

“APT28 appears to be moving rapidly to exploit this newly documented vulnerability before the available patch is widely deployed. Because Flash is still present on a high percentage of systems and this vulnerability affects all major operating systems, it is critical that organizations and end users apply the Adobe patch immediately. ” concluded Proofpoint.

Further technical details are available in the report published by Proofpoint, including the IOCs.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – APT28, cyber espionage)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/64611/apt/cve-2017-11292-apt28.html