Unsolved
This post is more than 5 years old
5 Journeyman
•
15.6K Posts
•
45K Points
0
12748
January 21st, 2015 14:00
Now PATCHED: 0-day exploit in Flash
Flash (having surpassed Java as the most-exploited browser plug-in) has been hit yet again: the Angler Exploit Kit will install Bedep, a distribution botnet that can load multiple payloads on the infected host.
According to MalwareBytes, users with the latest version of Internet Explorer and latest version of Flash, can successfully protect themselves by using [free] AntiExploit program https://www.malwarebytes.org/antiexploit/
For details, including which O/S and browsers have been confirmed vulnerable, see http://malware.dontneedcoffee.com/2015/01/unpatched-vulnerability-0day-in-flash.html
http://threatpost.com/exploit-for-flash-zero-day-appears-in-angler-exploit-kit/110569
https://blog.malwarebytes.org/exploits-2/2015/01/new-adobe-flash-zero-day-found-in-the-wild/


ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
January 22nd, 2015 04:00
Adobe Flash Player 16 has been updated to 16.0.0.287.
These updates address a vulnerability that could be used to circumvent memory randomization mitigations on the Windows platform.
Adobe is aware of reports that an exploit for CVE-2015-0310 exists in the wild, which is being used in attacks against older versions of Flash Player. Additionally, we are investigating reports that a separate exploit for Flash Player 16.0.0.287 and earlier also exists in the wild.
Documentation: http://helpx.adobe.com/security/products/flash-player/apsb15-02.html
It would appear that even this "emergency" update has NOT fully addressed the issue at hand!! --- they've released x.287, while saying that it too is subject to an exploit???
Direct downloads (no bundled junk) for Windows 7 and earlier :emotion-30::
Internet Explorer - http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_16_active_x.exe
Plugin-based browsers (Firefox etc) - http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_16_plugin.exe
Uninstaller (if needed) : http://download.macromedia.com/get/flashplayer/current/support/uninstall_flash_player.exe
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
January 22nd, 2015 09:00
From: http://threatpost.com/adobe-patches-one-zero-day-in-flash-still-investigating-separate-vulnerability
The vulnerability that Adobe patched Thursday is under active attack, but Adobe officials said that this flaw is NOT the one that security researcher Kafeine said Wednesday was being used in the Angler attacks.
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
January 24th, 2015 17:00
Users who have enabled auto-update for the Flash Player desktop runtime will be receiving version 16.0.0.296 beginning on January 24. This version includes a fix for CVE-2015-0311. Adobe expects to have an update available for manual download during the week of January 26.
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
January 25th, 2015 04:00
Adobe Flash Player 16 has been updated to 16.0.0.296.
This version includes a fix for CVE-2015-0311, a critical vulnerability [announced by "Kafeine" that] exists in Adobe Flash Player 16.0.0.287 and earlier versions for Windows and Macintosh. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.
Documentation: http://helpx.adobe.com/security/products/flash-player/apsa15-01.html
Direct downloads (no bundled junk) for Windows 7 and earlier :emotion-30::
Internet Explorer - http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_16_active_x.exe
Plugin-based browsers (Firefox etc) - http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_16_plugin.exe