CVE-2014-0569
published 2014-10-15CVE-2014-0569: Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR…
PriorityP186critical9.3CVSS 2.0
AVNACMAuNCCICAC
ITWEXPLOITVulnCheck KEVRansomware
Exploited in the wild
EPSS
90.21%
99.8th percentile
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allows attackers to execute arbitrary code via unspecified vectors.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air_desktop_runtime | <= 15.0.0.249 | — |
| adobe | air_sdk | <= 15.0.0.249 | — |
| adobe | air_sdk | <= 15.0.0.252 | — |
| adobe | flash_player | <= 11.2.202.406 | — |
| adobe | flash_player | <= 13.0.0.244 | — |
| adobe | flash_player | <= 15.0.0.152 | — |
| adobe | flash_player | <= 15.0.0.167 | — |
| adobe | flash_player_desktop_runtime | <= 15.0.0.167 | — |
| opensuse | evergreen | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_desktop | — | — |
Detection & IOCsextracted from sources · hover to see the quote
registryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL = http://127.0.0.1:[random]/[random]↗
- →The CVE-2014-0569 vulnerability is triggered via the casi32 method in Adobe Flash Player when a ByteArray of length 0 is set as domainMemory for the current application domain, causing an integer overflow. ↗
- →Exploit delivery uses a SWF file served with Content-Type application/x-shockwave-flash; detect HTTP responses serving .swf files with Cache-Control: no-cache, no-store headers in exploit kit traffic. ↗
- →KaiXin exploit kit delivered CVE-2014-0569 via malicious JavaScript from compromised websites or advertisements; monitor for KaiXin EK traffic patterns targeting Korean users. ↗
- →KRBanker payload uses Process Hollowing to execute malicious code inside a clean PE from the System directory; monitor for suspicious memory writes into system processes. ↗
- →KRBanker post-exploitation C2 registration uses HTTP GET to /ca.php with MAC address and code page parameters; detect this URI pattern in proxy/firewall logs. ↗
- →KRBanker abuses Proxy Auto-Config (PAC) by setting AutoConfigURL registry key to localhost; detect creation of HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL pointing to 127.0.0.1. ↗
- →KRBanker resolves pharming server IP by querying the QZone portrait API with a hardcoded QQ ID; detect outbound connections to users.qzone.qq.com/fcg-bin/cgi_get_portrait.fcg from non-browser processes. ↗
- →The Metasploit module targets Windows 7 SP1 (32-bit) with IE 8–11 and Flash 15.0.0.167 specifically; use this to scope detection to vulnerable browser/Flash version combinations. ↗
- ·The Metasploit module's BrowserRequirements restrict exploitation to Flash version exactly 15.0.0.167; the actual CVE affects a broader range (Flash before 13.0.0.250 and 14.x/15.x before 15.0.0.189 on Windows/OS X, before 11.2.202.411 on Linux). ↗
- ·The pharming server IP (23.107.204.38) is dynamically retrieved from a QZone SNS profile nickname field and is not hardcoded in the malware; the IP may change frequently across KRBanker variants. ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vulncheck9.3CRITICAL
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-43mw-6w68-5pvw: Integer overflow in Adobe Flash Player before 13
ghsa_unreviewed·2022-05-13
CVE-2014-0569 [HIGH] CWE-190 GHSA-43mw-6w68-5pvw: Integer overflow in Adobe Flash Player before 13
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allows attackers to execute arbitrary code via unspecified vectors.
OSV
CVE-2014-0569: Integer overflow in Adobe Flash Player before 13
osv·2014-10-15·CVSS 9.3
CVE-2014-0569 [CRITICAL] CVE-2014-0569: Integer overflow in Adobe Flash Player before 13
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allows attackers to execute arbitrary code via unspecified vectors.
VulnCheck
Adobe Flash Player Integer Overflow or Wraparound
vulncheck·2014·CVSS 9.3
CVE-2014-0569 [CRITICAL] Adobe Flash Player Integer Overflow or Wraparound
Adobe Flash Player Integer Overflow or Wraparound
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allows attackers to execute arbitrary code via unspecified vectors.
Affected: Adobe Flash Player
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.oreilly.com/content/threat-intelligence-and-ransomware/
Red Hat
flash-plugin: multiple code execution flaws (APSB14-22)
vendor_redhat·2014-10-14·CVSS 9.3
CVE-2014-0569 [CRITICAL] flash-plugin: multiple code execution flaws (APSB14-22)
flash-plugin: multiple code execution flaws (APSB14-22)
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allows attackers to execute arbitrary code via unspecified vectors.
No detection rules found.
Exploit-DB
Adobe Flash Player - casi32 Integer Overflow (Metasploit)
exploitdb·2015-04-13
CVE-2014-0569 Adobe Flash Player - casi32 Integer Overflow (Metasploit)
Adobe Flash Player - casi32 Integer Overflow (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class Metasploit3 'Adobe Flash Player casi32 Integer Overflow',
'Description' => %q{
This module exploits an integer overflow in Adobe Flash Player. The vulnerability occurs in
the casi32 method, where an integer overflow occurs if a ByteArray of length 0 is setup as
domainMemory for the current application domain. This module has been tested successfully
on Windows 7 SP1 (32-bit), IE 8 to IE 11 and Flash 15.0.0.167.
},
'License' => MSF_LICENSE,
'Author' =>
[
'bilou', # Vulnerability discovery
'juan vazquez' # msf module
],
'References' =>
[
['ZDI', '14-365'],
['CVE', '20
Metasploit
Adobe Flash Player casi32 Integer Overflow
metasploit
Adobe Flash Player casi32 Integer Overflow
Adobe Flash Player casi32 Integer Overflow
This module exploits an integer overflow in Adobe Flash Player. The vulnerability occurs in the casi32 method, where an integer overflow occurs if a ByteArray of length 0 is setup as domainMemory for the current application domain. This module has been tested successfully on Windows 7 SP1 (32-bit), IE 8 to IE 11 and Flash 15.0.0.167.
Unit42
KRBanker Targets South Korea Through Adware and Exploit Kits
blogs_unit42·2016-05-09·CVSS 9.3
[CRITICAL] KRBanker Targets South Korea Through Adware and Exploit Kits
Online banking services have been a prime target of cyber criminals for many years and attacks continue to grow. Targeting online banking users and stealing their credentials has yielded huge profits for the criminals behind these campaigns. Unit 42 has been tracking "KRBanker" AKA 'Blackmoon', since late last year. This campaign specifically targets banks of the Republic of Korea. On April 23, researchers at Fortinet published a blog describing the functionalities of the recent 'Blackmoon' campaign. Our objective in this blog is to share additional details on the distribution of the KRBanker or Blackmoon malware campaign and indicators of KRBanker samples.
Early variants of this campaign started surfacing in late September 2015. Though the number of KRBanker infection attempts was relati
Unit42
KRBanker Targets South Korea Through Adware and Exploit Kits
blogs_unit42·2016-05-09·CVSS 9.3
[CRITICAL] KRBanker Targets South Korea Through Adware and Exploit Kits
Threat Research Center
Threat Research
Malware
## KRBanker Targets South Korea Through Adware and Exploit Kits
Vicky Ray
Kaoru Hayashi
Published: May 9, 2016
Cybercrime
Malware
Threat Research
Adware
Banking Trojan
Blackmoon
ExploitKit
KRBanker
Pharming
Republic of Korea
Online banking services have been a prime target of cyber criminals for many years and attacks continue to grow. Targeting online banking users and stealing their credentials has yielded huge profits for the criminals behind these campaigns. Unit 42 has been tracking "KRBanker" AKA 'Blackmoon', since late last year. This campaign specifically targets banks of the Republic of Korea. On April 23, researchers at Fortinet published a blog describing the functionalities of the recent 'Blackmoon' campaign. Our
Recorded Future
Tracking Moving Targets: Exploit Kits and CVEs
blogs_recorded_future
Tracking Moving Targets: Exploit Kits and CVEs
# Tracking Moving Targets: Exploit Kits and CVEs
One year ago a notorious programmer Paunch, who coded the Blackhole exploit kit, was arrested and charged for the distribution and sale of his wares. Blackhole was an epic Russian exploit kit, rented and used by thousands for their successful campaigns against a range of targets.
Since Paunch’s arrest, the exploit kit threat landscape has changed significantly as malicious actors have sought out new tool kits. Recorded Future undertook the task of analyzing over 600,000 unique web sources to identify the most prevalent exploit kits, what CVEs they commonly leverage, and what the most vulnerable products are.
To get started, let’s craft a simple query looking for mentions of any exploit kit over the last six months.
###### Click image for
Bugzilla
CVE-2014-0564 CVE-2014-0558 CVE-2014-0569 flash-plugin: multiple code execution flaws (APSB14-22)
bugzilla·2014-10-14·CVSS 10.0
CVE-2014-0564 [CRITICAL] CVE-2014-0564 CVE-2014-0558 CVE-2014-0569 flash-plugin: multiple code execution flaws (APSB14-22)
CVE-2014-0564 CVE-2014-0558 CVE-2014-0569 flash-plugin: multiple code execution flaws (APSB14-22)
Adobe has released Flash Player 11.2.202.411 for Linux to correct the following flaws:
* These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2014-0564, CVE-2014-0558).
* These updates resolve an integer overflow vulnerability that could lead to code execution (CVE-2014-0569).
External References:
http://helpx.adobe.com/security/products/flash-player/apsb14-22.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2014:1648 https://rhn.redhat.com/errata/RHSA-2014-1648.html
http://helpx.adobe.com/security/products/flash-player/apsb14-22.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00033.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1648.htmlhttp://secunia.com/advisories/61980http://www.securityfocus.com/bid/70441http://www.securitytracker.com/id/1031019http://www.zerodayinitiative.com/advisories/ZDI-14-365/http://helpx.adobe.com/security/products/flash-player/apsb14-22.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00033.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1648.htmlhttp://secunia.com/advisories/61980http://www.securityfocus.com/bid/70441http://www.securitytracker.com/id/1031019http://www.zerodayinitiative.com/advisories/ZDI-14-365/
2014-10-15
Published
Exploited in the wild