4 ms·
Adobe confirms flash 0-day, issues security bulletin
- dougmccune 15y agoI think it's worth pointing out that this vulnerability is being exploited by people opening Word docs (on Windows) that they get via a phishing email. The last 0-day exploit against Flash that I saw posted on HN was the same thing but for a swf embedded in Excel. Not that these things aren't bad, but saying "Flash 0-day" sounds an awful lot more doomsday-ish than "0-day exploit if you open an attachment from a phishing email". Not trying to make excuses for Adobe, but people around here are pretty quick to jump on the overly-dramatic bandwagon when it comes to Flash.
- peepasaur 15y agoAgreed. There some fear-mongering with that type of headline. Of course, I had no idea that flash could even be embedded in Office applications.
- edge17 15y agoI mean... they just want to look responsible. If they'd toned it down, people would have accused them of not taking things seriously enough. It's better for them to seize the situation and own it rather than let the press have a field day and then spend time having to explain themselves. That's just my 2c...
- yuhong 15y agoSupport for embedding ActiveX controls in documents has been there since Office 97.
- jrockway 15y agoThis is not overly dramatic. Flash can now compromise your entire computer simply by your browser being directed at malicious content. It may be a search result, or a link, or an email... you click, and your entire computer is compromised. All your data could instantly disappear. All your money could be drained from your bank account. Remote exploits that require no abnormal user action are fucking serious.
- dougmccune 15y agoBut that's not what the exploit is. It's an exploit against a swf file embedded in a Word doc. So you have to open a bad Word doc. There's no evidence to suggest "you click, and your entire computer is compromised". This isn't just any random swf file on the web that you access with a browser (ie a search result or link). Instead it's "you get sent a shady email with an attachment, you ignore your better judgement about not opening shady attachments in emails, and then you're compromised".
- trotsky 15y agoThis flaw was packaged in a doc and spear-phished to specific people to achieve a specific goal. You are confusing features like "embedded in a .doc" and "unregulated by things like flashblock or noscript" with a limitation. While the initial attack is uninterested in you, these things spread widely. There is nothing that has been reported that suggests it is limited to this delivery vehicle - I would assume it is not. In my experience, 2nd or 3rd order exploitations will be active before an adobe fix is released.
- seanalltogether 15y agoI think his point was that this exploit was done outside of a browser sandbox, which places it in a whole new category of security issues. You could just as easily say this is microsofts fault for not applying stricter policies on activex controls within office products.
- jrockway 15y agoMan, Flash is like Windows 98 back in the day. Time to take the plunge and uninstall.
- trotsky 15y agoBackground on the advisory: http://krebsonsecurity.com/2011/04/new-adobe-flash-zero-day-being-exploited/ http://krebsonsecurity.com/2011/04/new-adobe-flash-zero-day-... According to sources, the attacks exploit a vulnerability in fully-patched versions of Flash, and are being leveraged in targeted spear-phishing campaigns launched against select organizations and individuals that work with or for the U.S. government. Sources say the attacks so far have embedded the Flash exploit inside of Microsoft Word files made to look like important government documents. Here's a virustotal scan of one of the documents: http://www.virustotal.com/file-scan/report.html?id=1e677420d7a8160c92b2f44f1ef5eea1cf9b0b1a25353db7d3142b268893507f-1302359653 http://www.virustotal.com/file-scan/report.html?id=1e677420d... The fact that one AV engine detected it as a 0-day was the source of admonishments or congratulations depending on where the observers stood. Until it was discussed that the one detection was probably an unrelated false positive. ~~~ Additional artifacts from the attack including the spearphising tease and the times they were being sent (early morning friday apr 8) - at the height of the budget battle. http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611...
- joeyh 15y agoHappy thank-goodness-I-removed-flash day. One of the best holidays, since I get to celebrate it so many times a year..
- beej71 15y ago"...and are being leveraged in targeted spear-phishing campaigns launched against select organizations and individuals that work with or for the U.S. government" Perhaps you work for or with the U.S. Government. Information leakage is fun! ;-)
- deleted 15y ago[deleted]
- deleted 15y ago[deleted]