CVE-2014-8440
published 2014-11-11CVE-2014-8440: Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356…
PriorityP273critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
81.94%
99.6th percentile
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0576, CVE-2014-0581, and CVE-2014-8441.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 15.0.0.356 | — |
| adobe | air_sdk | <= 15.0.0.356 | — |
| adobe | air_sdk_compiler | < 15.0.0.356 | 15.0.0.356 |
| adobe | flash_player | >= 11.0 < 11.2.202.418 | 11.2.202.418 |
| adobe | flash_player | >= 13.0 < 13.0.0.252 | 13.0.0.252 |
| adobe | flash_player | 14.0 – 14.0.0.179 | — |
| adobe | flash_player | >= 15.0 < 15.0.0.223 | 15.0.0.223 |
Detection & IOCsextracted from sources · hover to see the quote
- →The exploit delivers a malicious SWF file via HTTP with Content-Type 'application/x-shockwave-flash' and Cache-Control/Pragma no-cache headers; detect HTTP responses serving SWF content with these specific no-cache directives in combination with exploit landing pages. ↗
- →The exploit targets Internet Explorer (IE 8 / IE11) on Windows 7 SP1 (32-bit) with Adobe Flash 15.x (specifically tested on 15.0.0.189); scope detection to this browser/OS/Flash version combination. ↗
- →The exploit HTML template embeds a SWF via an <object> tag with FlashVars containing a base64-encoded PowerShell payload ('sh=<b64>'); detect HTML responses containing 'FlashVars' with a 'sh=' parameter holding a large base64 string. ↗
- →The exploit SWF filename is randomized (rand_text_alpha) with a .swf extension; the Metasploit module serves it from the path matching /\.swf$/ — monitor for randomized short-alpha .swf filenames served from exploit kit infrastructure. ↗
- →The vulnerability is triggered in ByteArray::UncompressViaZlibVariant; memory forensics or crash analysis showing uninitialized memory access in this Flash method is indicative of CVE-2014-8440 exploitation. ↗
- ·The Metasploit module requires the browser source to match /script|headers/i, OS to be Windows 7, UA to be Internet Explorer, and Flash version to match /^15\./ — the exploit will not trigger outside these constraints. ↗
- ·The exploit is architecture-specific (x86 only); 64-bit targets are not affected by this module. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: multiple code execution flaws (APSB14-24)
vendor_redhat·2014-11-11·CVSS 10.0
CVE-2014-0576 [CRITICAL] flash-plugin: multiple code execution flaws (APSB14-24)
flash-plugin: multiple code execution flaws (APSB14-24)
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0581, CVE-2014-8440, and CVE-2014-8441.
Red Hat
flash-plugin: multiple code execution flaws (APSB14-24)
vendor_redhat·2014-11-11·CVSS 10.0
CVE-2014-8440 [CRITICAL] flash-plugin: multiple code execution flaws (APSB14-24)
flash-plugin: multiple code execution flaws (APSB14-24)
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0576, CVE-2014-0581, and CVE-2014-8441.
Red Hat
flash-plugin: multiple code execution flaws (APSB14-24)
vendor_redhat·2014-11-11·CVSS 10.0
CVE-2014-8441 [CRITICAL] flash-plugin: multiple code execution flaws (APSB14-24)
flash-plugin: multiple code execution flaws (APSB14-24)
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0576, CVE-2014-0581, and CVE-2014-8440.
Red Hat
flash-plugin: multiple code execution flaws (APSB14-24)
vendor_redhat·2014-11-11·CVSS 10.0
CVE-2014-0581 [CRITICAL] flash-plugin: multiple code execution flaws (APSB14-24)
flash-plugin: multiple code execution flaws (APSB14-24)
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0576, CVE-2014-8440, and CVE-2014-8441.
GHSA
GHSA-6mfp-mq6h-245j: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2014-0581 [CRITICAL] GHSA-6mfp-mq6h-245j: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0576, CVE-2014-8440, and CVE-2014-8441.
GHSA
GHSA-h6r2-9pq2-qqww: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2014-8441 [CRITICAL] GHSA-h6r2-9pq2-qqww: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0576, CVE-2014-0581, and CVE-2014-8440.
GHSA
GHSA-r992-6q98-c5vh: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2014-0576 [CRITICAL] GHSA-r992-6q98-c5vh: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0581, CVE-2014-8440, and CVE-2014-8441.
GHSA
GHSA-r45g-2ph5-pcv3: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2014-8440 [CRITICAL] GHSA-r45g-2ph5-pcv3: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0576, CVE-2014-0581, and CVE-2014-8441.
OSV
CVE-2014-0576: Adobe Flash Player before 13
osv·2014-11-11·CVSS 10.0
CVE-2014-0576 [CRITICAL] CVE-2014-0576: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0581, CVE-2014-8440, and CVE-2014-8441.
OSV
CVE-2014-0581: Adobe Flash Player before 13
osv·2014-11-11·CVSS 10.0
CVE-2014-0581 [CRITICAL] CVE-2014-0581: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0576, CVE-2014-8440, and CVE-2014-8441.
OSV
CVE-2014-8440: Adobe Flash Player before 13
osv·2014-11-11·CVSS 10.0
CVE-2014-8440 [CRITICAL] CVE-2014-8440: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0576, CVE-2014-0581, and CVE-2014-8441.
OSV
CVE-2014-8441: Adobe Flash Player before 13
osv·2014-11-11·CVSS 10.0
CVE-2014-8441 [CRITICAL] CVE-2014-8441: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0576, CVE-2014-0581, and CVE-2014-8440.
No detection rules found.
Exploit-DB
Adobe Flash Player - UncompressViaZlibVariant Uninitialized Memory (Metasploit)
exploitdb·2015-05-01
CVE-2014-8440 Adobe Flash Player - UncompressViaZlibVariant Uninitialized Memory (Metasploit)
Adobe Flash Player - UncompressViaZlibVariant Uninitialized Memory (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class Metasploit3 'Adobe Flash Player UncompressViaZlibVariant Uninitialized Memory',
'Description' => %q{
This module exploits an unintialized memory vulnerability in Adobe Flash Player. The
vulnerability occurs in the ByteArray::UncompressViaZlibVariant method, which fails
to initialize allocated memory. When using a correct memory layout this vulnerability
leads to a ByteArray object corruption, which can be abused to access and corrupt memory.
This module has been tested successfully on Windows 7 SP1 (32-bit), IE 8 and IE11 with
Flash 15.0.0.189.
Metasploit
Adobe Flash Player UncompressViaZlibVariant Uninitialized Memory
metasploit
Adobe Flash Player UncompressViaZlibVariant Uninitialized Memory
Adobe Flash Player UncompressViaZlibVariant Uninitialized Memory
This module exploits an uninitialized memory vulnerability in Adobe Flash Player. The vulnerability occurs in the ByteArray::UncompressViaZlibVariant method, which fails to initialize allocated memory. When using a correct memory layout this vulnerability leads to a ByteArray object corruption, which can be abused to access and corrupt memory. This module has been tested successfully on Windows 7 SP1 (32-bit), IE 8 and IE11 with Flash 15.0.0.189.
Bugzilla
flash-plugin: multiple code execution flaws (APSB14-24)
bugzilla·2014-11-12·CVSS 10.0
CVE-2014-0576 [CRITICAL] flash-plugin: multiple code execution flaws (APSB14-24)
flash-plugin: multiple code execution flaws (APSB14-24)
Adobe has released Flash Player 11.2.202.418 for Linux to correct the following flaws:
* These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2014-0576, CVE-2014-0581, CVE-2014-8440, CVE-2014-8441).
* These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2014-0573, CVE-2014-0588, CVE-2014-8438).
* These updates resolve a double free vulnerability that could lead to code execution (CVE-2014-0574).
* These updates resolve type confusion vulnerabilities that could lead to code execution (CVE-2014-0577, CVE-2014-0584, CVE-2014-0585, CVE-2014-0586, CVE-2014-0590).
* These updates resolve heap buffer overflow vulnerabilities that could lead to code executi
Recorded Future
Tracking Moving Targets: Exploit Kits and CVEs
blogs_recorded_future
Tracking Moving Targets: Exploit Kits and CVEs
# Tracking Moving Targets: Exploit Kits and CVEs
One year ago a notorious programmer Paunch, who coded the Blackhole exploit kit, was arrested and charged for the distribution and sale of his wares. Blackhole was an epic Russian exploit kit, rented and used by thousands for their successful campaigns against a range of targets.
Since Paunch’s arrest, the exploit kit threat landscape has changed significantly as malicious actors have sought out new tool kits. Recorded Future undertook the task of analyzing over 600,000 unique web sources to identify the most prevalent exploit kits, what CVEs they commonly leverage, and what the most vulnerable products are.
To get started, let’s craft a simple query looking for mentions of any exploit kit over the last six months.
###### Click image for
http://helpx.adobe.com/security/products/flash-player/apsb14-24.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://www.securityfocus.com/bid/71047https://exchange.xforce.ibmcloud.com/vulnerabilities/98615https://www.exploit-db.com/exploits/36880/https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1081http://helpx.adobe.com/security/products/flash-player/apsb14-24.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://www.securityfocus.com/bid/71047https://exchange.xforce.ibmcloud.com/vulnerabilities/98615https://www.exploit-db.com/exploits/36880/https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1081
2014-11-11
Published