Second zero-day flaw found in Adobe Flash thanks to Hacking Team

Status
Not open for further replies.
S

sinu

Thread author
Earlier this week an exploit for Adobe Flash was revealed — a shock, I know. Now a second is in the wild and already being used. Known by the catchy name CVE-2015-5122, security firm FireEye discovered the flaw buried in the Hacking Team leak and alerted Adobe to it.

Adobe has released a security bulletin stating “Critical vulnerabilities (CVE-2015-5122, CVE-2015-5123) have been identified in Adobe Flash Player 18.0.0.204 and earlier versions for Windows, Macintosh and Linux. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system”.

The company categorizes this flaw as “critical”. FireEye points out that “The CVE-2015-5122 PoC is well written like the previous PoC for CVE-2015-5119 by the same author. The PoC also uses similar constructs for exploiting the Use-After-Free vulnerability in DisplayObject opaqueBackground“.

Affected versions include 18.0.0.203 for Windows and Mac, 18.0.0.204 for Linux, 13x versions for Windows and Mac and 11.2.2.481 for Linux.

Adobe is no stranger to these issues with its products, Flash especially. At the moment the bulletin mentions no fix, though one will certainly be coming.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
@Tony Cole : Flash security expose are already an ordinary cycle + that's the only software design to play videos. If you're habit is just viewing videos on same sites then a very low chance to be infected.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top