Jump to content
Aerosol

Adobe admits to another Flash Player zero-day flaw

Recommended Posts

Posted

security-risk-summit-270x167.jpg?1403887029

ADOBE FLASH IS VULNERABLE again, Adobe has warned. The company released a new security bulletin acknowledging a zero-day flaw in Flash Player which was exploited throughout January.

Classified with a 'critical' severity rating, the CVE-2015-0313 flaw affects Flash Player 16.0.0.296 and earlier versions on Windows and OS X machines.

A successful exploitation "could cause a crash and potentially allow an attacker to take control of the affected system", Adobe warned.

The company thanked security researchers from Microsoft and Trend Micro for reporting the flaw.

The vulnerability is being exploited via drive-by download attacks against users of Internet Explorer and Firefox on Windows 8.1, Adobe said.

Trend Micro said that the flaw has been exploited by cyber criminals with 'malvertising' campaigns that redirect visitors from a legitimate site to a malicious domain where the exploit is hosted.

Using the ad-serving network allows the criminals to maximise the attack surface while spreading the infection automatically on vulnerable systems, the security firm explained.

Most of those who accessed the malicious server in January were located in the US, Trend Micro said. The popular video sharing site Dailymotion was one site affected by the vulnerability.

January was a busy period for Flash Player, with two critical flaws already discovered and patched by Adobe near the end of the month. The company said that a fixed version of Flash Player will be released this week.

Andy Manoske of security company AlienVault said that Flash "is extremely prolific with something like ~20% penetration of all active websites on the web", and that there is "an incredible amount of scrutiny on Flash" from researchers and criminals.

The software's complicated architecture isn't helpful in avoiding the discovery of new vulnerabilities, the researcher warned.

Source

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...