PSA: Flash Vulnerability found

rasczak

Lifer
Jan 29, 2005
10,437
23
81
Just an FYI. Sorry if this is a repost. I searched and found nothing.


http://blogs.zdnet.com/security/?p=1189

Malware hunters have spotted a previously unknown ? and unpatched ? Adobe Flash vulnerability being exploited in the wild.

The zero-day flaw has been added to the Chinese version of the MPack exploit kit and there are signs that the exploits are being injected into third-party sites to redirect targets to malware-laden servers.

Technical details on the vulnerability are not yet available. Adobe?s product security incident response team is investigating.

This SecurityFocus advisory warns:

Adobe Flash Player is prone to an unspecified remote code-execution vulnerability.

An attacker may exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.

Adobe Flash Player 9.0.115.0 and 9.0.124.0 are vulnerable; other versions may also be affected.

I?ve independently verified that redirection scripts have been posted on at least two Chinese-language Web sites to launch drive-by downloads of malware. When the exploit fires, it checks the Flash version on the vulnerable computer and, depending on the result, it uses a different .SWF (shockwave) file to take complete control of the machine.

This threat should be considered very serious because of the widespread distribution that Adobe Flash enjoys on the Windows ecosystem. If this exploit gets seeded on high-traffic Web sites, we could be in for a long clean-up operation.

More from the SANS ISC diary.

[ UPDATE: Continued investigation reveals this issue is fairly widespread. Malicious code is being injected into other third-party domains (approximately 20,000 web pages) most likely through SQL-injection attacks. The code then redirects users to sites hosting malicious Flash files exploiting this issue.]





 

Auggie

Golden Member
Jul 18, 2003
1,379
0
0
alright... so don't go to any websites with flash? aren't there flash adds all over ATOT? We just have to trust that the hosts for the flash adds aren't compromised? (btw, I use AdBlocker, so I don't see much flash anywhere I go)

speaking of which - youtube would be a great target for this exploit.
 

Zim Hosein

Super Moderator | Elite Member
Super Moderator
Nov 27, 1999
65,409
407
126
Originally posted by: AmigaMan
<laughs at the funny Windows users/>
:p

<-- Laughs at AmigaMan for paying a premium on computer hardware! :p
 

nsafreak

Diamond Member
Oct 16, 2001
7,093
3
81
Originally posted by: Random Variable
the last version of Flash (9.0.124.0) is apparently not vulnerable

According to the article:

Adobe Flash Player 9.0.115.0 and 9.0.124.0 are vulnerable; other versions may also be affected.

So unless something has recently changed it is vulnerable. Kindof makes me wonder if older flash versions are not vulnerable.
 
Aug 10, 2001
10,420
2
0
A vulnerability in Flash Player 9 is being actively exploited. The latest version of Flash Player (9.0.124.0) appears to correct the vulnerability. Analysis indicates that this vulnerability is the same as or similar to the one described in Application Specific Attacks: Leveraging the ActionScript Virtual Machine by Mark Dowd. The vulnerability depends on ActionScript 3.0 which was introduced in Flash Player 9, so previous versions do not appear to be affected.

http://www.us-cert.gov/cas/techalerts/TA08-149A.html
 

jlee

Lifer
Sep 12, 2001
48,518
223
106
Whoa, I'm way behind the times...last I heard, it was Macromedia Flash. :confused:
 

sciencewhiz

Diamond Member
Jun 30, 2000
5,885
8
81
Originally posted by: nsafreak
Originally posted by: Random Variable
the last version of Flash (9.0.124.0) is apparently not vulnerable

According to the article:

Adobe Flash Player 9.0.115.0 and 9.0.124.0 are vulnerable; other versions may also be affected.

So unless something has recently changed it is vulnerable. Kindof makes me wonder if older flash versions are not vulnerable.

Security Focus has corrected their description and says that 9.0.124 is not vulnerable. All earlier versions of Flash 9 are vulnerable, but Flash 8 and earlier are not.
 

crystal

Platinum Member
Nov 5, 1999
2,424
0
76
It must be something because when I log on to WoW this morning, it got a notice about this thing. hehe...