CVE-2014-0556
published 2014-09-10CVE-2014-0556: Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux…
PriorityP185critical10CVSS 2.0
AVNACLAuNCCICAC
ITWEXPLOITVulnCheck KEVRansomware
Exploited in the wild
EPSS
84.30%
99.7th percentile
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0559.
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_air | <= 14.0.0.178 | — |
| adobe | adobe_air | <= 14.0.0.179 | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air_sdk | <= 14.0.0.178 | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | flash_player | <= 13.0.0.241 | — |
| adobe | flash_player | <= 11.2.202.400 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2014-0556 was actively included in the Nuclear Pack exploit kit to deliver CryptoWall 2.0 ransomware; monitor for exploit kit traffic patterns delivering SWF payloads. ↗
- →The Metasploit exploit module serves a malicious SWF file with Content-Type 'application/x-shockwave-flash'; detect HTTP responses delivering .swf files with no-cache headers to browsers matching Windows 7 / IE user-agents. ↗
- →The exploit targets the copyPixelsToByteArray method of the BitmapData object in Flash; look for SWF files invoking this method with anomalous ByteArray position values. ↗
- →The Metasploit module targets Windows 7 SP1 (32-bit) with IE 8–11 and Flash versions 14.0.0.176, 14.0.0.145, 14.0.0.125, and 14.0.0.179; prioritize detection on these specific browser/Flash version combinations. ↗
- →CryptoWall 2.0 payloads were delivered as .scr and .exe attachments in emails with fake invoice, fax, and voicemail themes; flag inbound email attachments with these extensions and naming patterns. ↗
- ·The Metasploit module's browser requirements restrict exploitation to Windows 7 with IE user-agent and Flash versions in the 14.x range; the module will not trigger against other OS/browser combinations. ↗
- ·The NVD entry provided (CVE-2014-0559) is a different but related heap-based buffer overflow vulnerability in Adobe Flash Player; do not conflate its affected version ranges with CVE-2014-0556. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8w86-7v7g-746r: Heap-based buffer overflow in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2014-0556 [CRITICAL] CWE-119 GHSA-8w86-7v7g-746r: Heap-based buffer overflow in Adobe Flash Player before 13
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0559.
GHSA
GHSA-v9v5-f3pq-3qxp: Heap-based buffer overflow in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2014-0559 [CRITICAL] CWE-119 GHSA-v9v5-f3pq-3qxp: Heap-based buffer overflow in Adobe Flash Player before 13
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0556.
OSV
CVE-2014-0556: Heap-based buffer overflow in Adobe Flash Player before 13
osv·2014-09-10·CVSS 10.0
CVE-2014-0556 [CRITICAL] CVE-2014-0556: Heap-based buffer overflow in Adobe Flash Player before 13
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0559.
OSV
CVE-2014-0559: Heap-based buffer overflow in Adobe Flash Player before 13
osv·2014-09-10·CVSS 10.0
CVE-2014-0559 [CRITICAL] CVE-2014-0559: Heap-based buffer overflow in Adobe Flash Player before 13
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0556.
Project0
Exploiting CVE-2014-0556 in Flash - Project Zero
project_zero·2014-09-01·CVSS 10.0
CVE-2014-0556 [CRITICAL] Exploiting CVE-2014-0556 in Flash - Project Zero
Posted by Chris Evans, Kidnapper of RIP
A couple of weeks ago, Adobe released security bulletin APSB14-21, including 8 fixes for bugs reported by Project Zero. Full details of these bugs are now public in our bug tracker. Some of the more interesting ones are a double free in the RTMP protocol, or an integer overflow concatenating strings. Again, we’d like to thank Adobe for a response time well ahead of our standard 90-day disclosure deadline.
The focus of this post is an integer overflow leading to a buffer overflow in an ActionScript API.
Prelude
Before we get started, though, it’s worth briefly noting why there is so much value in writing an exploit. Finding and eliminating bugs obviously improves software correctness, but writing exploits is always a significant learning opport
VulnCheck
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2014·CVSS 10.0
CVE-2014-0556 [CRITICAL] Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0559.
Affected: Adobe Flash Player
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://unit42.paloalton
Red Hat
flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
vendor_redhat·2014-09-09·CVSS 10.0
CVE-2014-0556 [CRITICAL] flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0559.
Red Hat
flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
vendor_redhat·2014-09-09·CVSS 10.0
CVE-2014-0559 [CRITICAL] flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0556.
No detection rules found.
Exploit-DB
Adobe Flash Player - copyPixelsToByteArray Integer Overflow (Metasploit)
exploitdb·2015-04-21
CVE-2014-0556 Adobe Flash Player - copyPixelsToByteArray Integer Overflow (Metasploit)
Adobe Flash Player - copyPixelsToByteArray Integer Overflow (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class Metasploit3 'Adobe Flash Player copyPixelsToByteArray Integer Overflow',
'Description' => %q{
This module exploits an integer overflow in Adobe Flash Player. The vulnerability occurs
in the copyPixelsToByteArray method from the BitmapData object. The position field of the
destination ByteArray can be used to cause an integer overflow and write contents out of
the ByteArray buffer. This module has been tested successfully on Windows 7 SP1 (32-bit),
IE 8 to IE 11 and Flash 14.0.0.176, 14.0.0.145 and 14.0.0.125.
},
'License' => MSF_LICENSE,
'Author' =>
[
Metasploit
Adobe Flash Player copyPixelsToByteArray Method Integer Overflow
metasploit
Adobe Flash Player copyPixelsToByteArray Method Integer Overflow
Adobe Flash Player copyPixelsToByteArray Method Integer Overflow
This module exploits an integer overflow in Adobe Flash Player. The vulnerability occurs in the copyPixelsToByteArray method from the BitmapData object. The position field of the destination ByteArray can be used to cause an integer overflow and write contents out of the ByteArray buffer. This module has been tested successfully on: * Windows 7 SP1 (32-bit), IE 8 to IE 11 and Flash 14.0.0.176, 14.0.0.145, and 14.0.0.125. * Windows 7 SP1 (32-bit), Firefox 38.0.5 and Adobe Flash 14.0.0.179. * Windows 8.1, Firefox 38.0.5 and Adobe Flash 14.0.0.179.
Unit42
Tracking New Ransomware CryptoWall 2.0
blogs_unit42·2014-10-22
Tracking New Ransomware CryptoWall 2.0
## Tracking New Ransomware CryptoWall 2.0
Ryan Olson
Published: October 22, 2014
Ransomware
Threat Research
Bitcoin
CryptoWall
CryptoWall 2.0
Tor
The latest development in the ransomware world is CryptoWall 2.0, a new version of this malware family that uses the Tor network for command and control.
F-Secure was the first to spot this new version on October 1, but since then the attacks have ramped up and new variants of the malware are emerging daily. Our WildFire analysis platform has picked up 84 CryptoWall 2.0 variants since September 30, delivered primarily through e-mail attachments but also through malicious PDFs and web exploit kits.
CryptoWall 2.0 is similar to other ransomware attacks that have plagued users and businesses for nearly a decade. Once it is running on a s
Unit42
Tracking New Ransomware CryptoWall 2.0
blogs_unit42·2014-10-22
Tracking New Ransomware CryptoWall 2.0
The latest development in the ransomware world is CryptoWall 2.0, a new version of this malware family that uses the Tor network for command and control.
F-Secure was the first to spot this new version on October 1, but since then the attacks have ramped up and new variants of the malware are emerging daily. Our WildFire analysis platform has picked up 84 CryptoWall 2.0 variants since September 30, delivered primarily through e-mail attachments but also through malicious PDFs and web exploit kits.
CryptoWall 2.0 is similar to other ransomware attacks that have plagued users and businesses for nearly a decade. Once it is running on a system, CryptoWall 2.0 seeks out document files and encrypts them using the RSA encryption algorithm. The attacker holds the key necessary to decrypt the fil
Recorded Future
Tracking Moving Targets: Exploit Kits and CVEs
blogs_recorded_future
Tracking Moving Targets: Exploit Kits and CVEs
# Tracking Moving Targets: Exploit Kits and CVEs
One year ago a notorious programmer Paunch, who coded the Blackhole exploit kit, was arrested and charged for the distribution and sale of his wares. Blackhole was an epic Russian exploit kit, rented and used by thousands for their successful campaigns against a range of targets.
Since Paunch’s arrest, the exploit kit threat landscape has changed significantly as malicious actors have sought out new tool kits. Recorded Future undertook the task of analyzing over 600,000 unique web sources to identify the most prevalent exploit kits, what CVEs they commonly leverage, and what the most vulnerable products are.
To get started, let’s craft a simple query looking for mentions of any exploit kit over the last six months.
###### Click image for
Bugzilla
CVE-2014-0547 CVE-2014-0549 CVE-2014-0550 CVE-2014-0551 CVE-2014-0552 CVE-2014-0553 CVE-2014-0554 CVE-2014-0555 CVE-2014-0556 CVE-2014-0557 CVE-2014-0559 flash-plugin: multiple code execution or secur
bugzilla·2014-09-09·CVSS 10.0
CVE-2014-0547 [CRITICAL] CVE-2014-0547 CVE-2014-0549 CVE-2014-0550 CVE-2014-0551 CVE-2014-0552 CVE-2014-0553 CVE-2014-0554 CVE-2014-0555 CVE-2014-0556 CVE-2014-0557 CVE-2014-0559 flash-plugin: multiple code execution or secur
CVE-2014-0547 CVE-2014-0549 CVE-2014-0550 CVE-2014-0551 CVE-2014-0552 CVE-2014-0553 CVE-2014-0554 CVE-2014-0555 CVE-2014-0556 CVE-2014-0557 CVE-2014-0559 flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
Adobe has released Flash Player 11.2.202.406 for Linux to correct the following flaws:
* These updates resolve memory leakage vulnerabilities that could be used to bypass memory address randomization (CVE-2014-0557).
* These updates resolve a security bypass vulnerability (CVE-2014-0554).
* These updates resolve a use-after-free vulnerability that could lead to code execution (CVE-2014-0553).
* These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2014-0547, CVE-2014-0549, CVE-2014-0550, CVE-2014-0551, CVE-2014-0552, CV
http://googleprojectzero.blogspot.com/2014/09/exploiting-cve-2014-0556-in-flash.htmlhttp://helpx.adobe.com/security/products/flash-player/apsb14-21.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00021.htmlhttp://packetstormsecurity.com/files/131516/Adobe-Flash-Player-copyPixelsToByteArray-Integer-Overflow.htmlhttp://secunia.com/advisories/61089http://security.gentoo.org/glsa/glsa-201409-05.xmlhttp://www.osvdb.org/111110http://www.securityfocus.com/bid/69696http://www.securitytracker.com/id/1030822https://code.google.com/p/google-security-research/issues/detail?id=46https://exchange.xforce.ibmcloud.com/vulnerabilities/95826https://www.exploit-db.com/exploits/36808/http://googleprojectzero.blogspot.com/2014/09/exploiting-cve-2014-0556-in-flash.htmlhttp://helpx.adobe.com/security/products/flash-player/apsb14-21.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00021.htmlhttp://packetstormsecurity.com/files/131516/Adobe-Flash-Player-copyPixelsToByteArray-Integer-Overflow.htmlhttp://secunia.com/advisories/61089http://security.gentoo.org/glsa/glsa-201409-05.xmlhttp://www.osvdb.org/111110http://www.securityfocus.com/bid/69696http://www.securitytracker.com/id/1030822https://code.google.com/p/google-security-research/issues/detail?id=46https://exchange.xforce.ibmcloud.com/vulnerabilities/95826https://www.exploit-db.com/exploits/36808/
2014-09-10
Published
Exploited in the wild