20,000 Web pages help exploit 'patched' Flash flaw

A possible zero day exploit has been discovered for a flaw in Flash thought to have been patched by Adobe a month ago.

Symantec researchers claim the exploit has several different payloads, including one to steal passwords from systems with the vulnerable software. Affected versions of Adobe Flash Player include 9.0.124.0 (latest version) and 9.0.115.0.

Around 20,000 legitimate Web pages have been manipulated, likely via SQL-injection vulnerabilities, to redirect browsers to domains in China which host the exploit, according to Vincent Weafer, senior director of development for Symantec's Security Response team.

The buffer overflow flaw being exploited occurs when processing Shock Wave Files (SWF) and was meant to be resolved by a patch Adobe issued in April, according to Symantec. However, there's still some uncertainty as to whether the exploit discovered today uses exactly the same flaw patched last month.

"We believe this is very similar to a previous reported vulnerability that was tracked down by IBM. However, the exploit we found in the wild is successful against the latest release of Adobe Flash, so we believe it's a variation of that vulnerability," Weafer said.

Want to know more?

For all the latest news, analysis and opinion on security, click here

Last month, IBM security researcher Mark Dowd released a research note predicting a rise in use of Flash flaws to exploit computer systems.

"The reason we put out the research is to draw attention to how serious these types of vulnerabilities can be," Dowd told ZDNet.com.au at the time.

Adobe says it is investigating the "potential SWF vulnerability", however, the company has not yet released further information.

Novologica security consultant, Nishad Herath, said it doesn't matter whether Adobe confirms the exploit is a zero day.

"It exploits the latest version so it doesn't matter too much whether they call it a variant of an old flaw that wasn't patched properly. It makes little difference," Herath told ZDNet.com.au.

Symantec's Weafer said consumers and businesses should disable Java script, ensure that data execution prevention is enabled in Windows and block access to malicious IP addresses. He added that most antivirus and intrusion prevention systems will detect the malware.

Advertisement

Talkback 1 comments

    Flash Exploit updatebob -- 29/05/08

    According to Adobe Product Security Incident Response Team (PSIRT) blog,
    http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue_u_1.html

    "We've just gotten confirmation from Symantec that all versions of Flash Player 9.0.124.0 are not vulnerable to these exploits"
    (this was taken from the update section of the page


Latest Videos

Blogs

  • David Braue Will Rudd's bush backhaul bonanza deliver?
    Rural areas will be welcoming the government's decision to put its money where its politicising is, funnelling $250m into a regional fibre upgrade to six rural centres. Remedying over a decade of near-neglect at the hands of telecoms privatisation, the investment could be the firmest step yet for Labor's NBN dream — but with inevitable political questions and a looming election, Rudd and Conroy need to deliver, and quickly, to preserve the NBN's credibility.
  • Array Doing for AV what VoIP did for telephony
    Sydney-based start-up Audinate is making traditional analog cabling obsolete in favour of TCP/IP-based networking technology. And it's doing a pretty good job so far, with its technology used by World Youth Day and the Sydney Opera House.
  • Array WiMax in Australia: Part two
    WiMax could be the standard that drives the next phase of mobile broadband, it provides an opportunity for players wanting to establish a pure IP network to carry voice and data effectively — but is this what operators want?
  • More blogs »

Tags

Back to top

Featured