Unsolved

This post is more than 5 years old

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

12748

January 21st, 2015 14:00

Now PATCHED: 0-day exploit in Flash

Flash (having surpassed Java as the most-exploited browser plug-in) has been hit yet again:  the Angler Exploit Kit will install Bedep, a distribution botnet that can load multiple payloads on the infected host.

According to MalwareBytes, users with the latest version of Internet Explorer and latest version of Flash, can successfully protect themselves by using [free] AntiExploit program https://www.malwarebytes.org/antiexploit/

For details, including which O/S and browsers have been confirmed vulnerable, see  http://malware.dontneedcoffee.com/2015/01/unpatched-vulnerability-0day-in-flash.html 

http://threatpost.com/exploit-for-flash-zero-day-appears-in-angler-exploit-kit/110569

https://blog.malwarebytes.org/exploits-2/2015/01/new-adobe-flash-zero-day-found-in-the-wild/

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

January 22nd, 2015 04:00

Adobe Flash Player 16 has been updated to 16.0.0.287.

These updates address a vulnerability that could be used to circumvent memory randomization mitigations on the Windows platform.  

Adobe is aware of reports that an exploit for CVE-2015-0310 exists in the wild, which is being used in attacks against older versions of Flash Player.  Additionally, we are investigating reports that a separate exploit for Flash Player 16.0.0.287 and earlier also exists in the wild.  

Documentation:   http://helpx.adobe.com/security/products/flash-player/apsb15-02.html

It would appear that even this "emergency" update has NOT fully addressed the issue at hand!! --- they've released x.287, while saying that it too is subject to an exploit??? :blink:

Direct downloads (no bundled junk) for Windows 7 and earlier :emotion-30::

Internet Explorer -  http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_16_active_x.exe

Plugin-based browsers (Firefox etc) - http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_16_plugin.exe

Uninstaller (if needed) : http://download.macromedia.com/get/flashplayer/current/support/uninstall_flash_player.exe

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

January 22nd, 2015 09:00

From:  http://threatpost.com/adobe-patches-one-zero-day-in-flash-still-investigating-separate-vulnerability

The vulnerability that Adobe patched Thursday is under active attack, but Adobe officials said that this flaw is NOT the one that security researcher Kafeine said Wednesday was being used in the Angler attacks.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

January 24th, 2015 17:00

Users who have enabled auto-update for the Flash Player desktop runtime will be receiving version 16.0.0.296 beginning on January 24. This version includes a fix for CVE-2015-0311. Adobe expects to have an update available for manual download during the week of January 26.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

January 25th, 2015 04:00

Adobe Flash Player 16 has been updated to 16.0.0.296.

This version includes a fix for CVE-2015-0311, a critical vulnerability [announced by "Kafeine" that] exists in Adobe Flash Player 16.0.0.287 and earlier versions for Windows and Macintosh.  Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system. 

Documentation:   http://helpx.adobe.com/security/products/flash-player/apsa15-01.html

Direct downloads (no bundled junk) for Windows 7 and earlier :emotion-30::

Internet Explorer -  http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_16_active_x.exe

Plugin-based browsers (Firefox etc) - http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_16_plugin.exe

No Events found!

Top