AddThis Social Bookmark Button
Free Dating
search My Threads  

Main    Computers & Technology   

Heads-up: "Adobe Flash zero-day exploit in the wild"


May 27 @ 6:03 PM Heads-up: "Adobe Flash zero-day exploit in the wild"    
nah12


Posts: 2,963
no patch at this time.....

Malware hunters have spotted a previously unknown — and unpatched — Adobe Flash vulnerability being exploited in the wild.

The zero-day flaw has been added to the Chinese version of the MPack exploit kit and there are signs that the exploits are being injected into third-party sites to redirect targets to malware-laden servers.

Technical details on the vulnerability are not yet available. Adobe’s product security incident response team is investigating.

This SecurityFocus advisory warns:

Adobe Flash Player is prone to an unspecified remote code-execution vulnerability.

An attacker may exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.

Adobe Flash Player 9.0.115.0 and 9.0.124.0 are vulnerable; other versions may also be affected.

I’ve independently verified that redirection scripts have been posted on at least two Chinese-language Web sites to launch drive-by downloads of malware. When the exploit fires, it checks the Flash version on the vulnerable computer and, depending on the result, it uses a different .SWF (shockwave) file to take complete control of the machine.

This threat should be considered very serious because of the widespread distribution that Adobe Flash enjoys on the Windows ecosystem. If this exploit gets seeded on high-traffic Web sites, we could be in for a long clean-up operation.

More from the SANS ISC diary.

[ UPDATE: Continued investigation reveals this issue is fairly widespread. Malicious code is being injected into other third-party domains (approximately 20,000 web pages) most likely through SQL-injection attacks. The code then redirects users to sites hosting malicious Flash files exploiting this issue.]
Adobe Flash zero-day exploit in the wild
post reply view nah12's threads
May 27 @ 6:40 PM Heads-up: "Adobe Flash zero-day exploit in the wild"    
sealacamp


Posts: 2,798
Thanks for the heads up nah. No more flash games, at least for a while. I guess if they can't attack you directly through windows those vicious nuts will find some other doorway.

S
post reply view sealacamp's threads
May 27 @ 11:25 PM Heads-up: "Adobe Flash zero-day exploit in the wild"    
mystery2u888


Posts: 4,397
Nah.............. thanks.........hey Seal
post reply view mystery2u888's threads
Main    Computers & Technology    Heads-up: "Adobe Flash zero-day exploit in the wild"

free adult dating | mission statement | testimonials | safety warning | report abuse | safe list | privacy | legal | advertise | link to us

© Copyright 2000-2008 Online Singles, LLC.
WEB2