This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

0-day exploit in the wild - Adobe Flash player...

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://blogs.adobe.com/psirt/2009/07/poten…er_and_fla.html
July 21, 2009 - "Adobe is aware of reports of a potential vulnerability in Adobe Reader and Acrobat 9.1.2 and Adobe Flash Player 9 and 10. We are currently investigating this potential issue and will have an update once we get more information."

> http://isc.sans.org/diary.html?storyid=6847
Last Updated: 2009-07-22 22:26:39 UTC …(Version: 3) - "… the vulnerable component is actually the Flash player or, better said, the code used by the Flash player which is obviously shared with Adobe Reader/Acrobat. This increases the number of vectors for this attack: the malicious Flash file can be embedded in PDF documents which will cause Adobe Reader to execute it OR it can be used to exploit the Flash player directly, making it a drive-by attack as well. And indeed, when tested with Internet Explorer and the latest Flash player (version 10), the exploit silently drops a Trojan and works "as advertised". Another interesting thing I noticed is that the Trojan, which is downloaded in the second stage, is partially XOR-ed – the attackers probably did this to evade IDSes or AV programs scanning HTTP traffic. At the moment, the detection for both the exploit and the Trojan is pretty bad (only 7/41 for the Trojan, according to VirusTotal*)…
UPDATE: At the moment there is a low number of malicious sites serving the exploit, but we confirmed that the links have been injected in legitimate web sites to create a drive-by attack, as expected. It appears that the attackers created two different shellcodes as well, one for Firefox users (still have to confirm this) and the other for Internet Explorer users (this one is -confirmed- to work)."
* http://preview.tinyurl.com/l3wg89
File 34d6452000e1a9e0308702d082c897008a0481b0.EXE received on 2009.07.22 16:49:07 (UTC)
Result: 7/41 (17.07%)

- http://www.us-cert.gov/current/#adobe_read…robat_and_flash

- http://www.kb.cert.org/vuls/id/259425
2009-07-22

- http://blogs.technet.com/srd/archive/2009/…ogy-part-2.aspx
June 12, 2009
> FixIt4Me - Enable DEP for Office
> FixIt4Me - Enable DEP for IE


- http://www.theregister.co.uk/2009/07/22/ad…ttacks_go_wild/
22 July 2009

Update on Adobe Reader, Acrobat and Flash Player Issue
- http://blogs.adobe.com/psirt/2009/07/updat…er_acrobat.html
July 22, 2009 7:08 PM

:ph34r: <_< :ph34r:
FYI…

- http://www.adobe.com/support/security/advi…/apsa09-03.html
July 22, 2009 - "… We are in the process of developing a fix for the issue, and expect to provide an update for Flash Player v9 and v10 for Windows, Macintosh, and Linux by July 30, 2009 (the date for Flash Player v9 and v10 for Solaris is still pending). We expect to provide an update for Adobe Reader and Acrobat v9.1.2 for Windows and Macintosh by July 31, 2009…"

- http://securitylabs.websense.com/content/Alerts/3449.aspx
07.23.2009

- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-1862
Last revised: 07/24/2009

- http://www.securityfocus.com/bid/35759/info
Updated: Jul 23 2009

- http://bugs.adobe.com/jira/browse/FP-1265
Created: 12/31/08

- http://www.symantec.com/business/security_…-99&tabid=2
Discovered: July 22, 2009 - "…The Trojan arrives in a specially crafted .pdf file that exploits a vulnerability in Adobe Flash Player. When executed the Trojan drops the following files on the compromised computer:
* %Temp%\SUCHOST.EXE (Trojan Horse)
* %Temp%\TEMP.EXE (A non-malicious file.)
Note: The SUCHOST.EXE file may open a back door that connects to the following domains:
* http ://aop1.homelinux .com
* http ://connectproxy.3322 .org
* http ://csport.2288 .org …" [DO NOT VISIT]

:huh: :blink:
FYI…

- http://www.adobe.com/support/security/advi…/apsa09-04.html
July 28, 2009 - "Adobe Flash Player 9.0.159.0 and 10.0.22.87, and earlier 9.x and 10.x versions installed on Windows operating systems for use with Internet Explorer leverage a vulnerable version of the Microsoft Active Template Library (ATL) described in Microsoft Security Advisory (973882). This critical vulnerability could allow an attacker who successfully exploits the vulnerability to take control of the affected system.

Note that this vulnerability is exclusive to Internet Explorer on Windows. Installations of Flash Player for Firefox or other web browsers on Windows are -not- vulnerable. We are in the process of developing a fix for the issue, and expect to provide an update for Flash Player v9 and v10 for Windows by July 30, 2009.

Users should consider installing MS09-034*. As a defense-in-depth measure, this Internet Explorer security update helps mitigate known attack vectors within Internet Explorer for those components and controls, such as Flash Player, that have been developed with vulnerable versions of ATL as described in Microsoft Security Advisory (973882) and Microsoft Security Bulletin MS09-035**…"

* http://www.microsoft.com/technet/security/…n/ms09-034.mspx

** http://www.microsoft.com/technet/security/…n/ms09-035.mspx

- http://secunia.com/advisories/35948/2/
Solution Status: Unpatched
Software: Adobe Flash Player 10.x, Adobe Flash Player 9.x …
Changelog: 2009-07-29: Added information about control having been built using a vulnerable version of ATL.

:ph34r:
FYI…

Flash Player v10.0.32.18 released
- http://forums.whatthetech.com/index.php?s=…st&p=583391

Adobe Shockwave v11.5.1.601 released
- http://forums.whatthetech.com/index.php?s=…st&p=582834

- http://www.adobe.com/support/security/bull…/apsb09-11.html
Release date: July 28, 2009 - "… Adobe recommends Shockwave Player users on Windows install Shockwave version 11.5.1.601 …"

- http://www.adobe.com/support/security/bull…/apsb09-10.html
Last revised: August 3, 2009 - "… Adobe recommends all users of Adobe Flash Player… upgrade to the newest version 10.0.32.18…"

Test both here: http://www.adobe.com/shockwave/welcome/

:ph34r: :ph34r: