cbcvebase.
CVE-2015-3133
published 2015-07-09

CVE-2015-3133: Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180…

PriorityP275critical10CVSS 2.0
AVNACLAuNCCICAC
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
5.31%
91.7th percentile
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3134, and CVE-2015-4431.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
adobeair<= 18.0.0.144
adobeair_sdk<= 18.0.0.144
adobeair_sdk_compiler<= 18.0.0.144
adobeflash_player<= 11.2.202.468
adobeflash_player<= 13.0.0.289
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player

Detection & IOCsextracted from sources · hover to see the quote

domainwww.newspot[.]kr/config.php?sUID=[web site name]
ip23.107.204[.]38
urlhttp://[IP address]/ca.php?m=[encoded MAC Address]&h=[code page]
registryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL = http://127.0.0.1:[random]/[random]
urlhttps://github.com/pan-unit42/iocs/blob/master/krbanker/hashes.txt
domainusers.qzone.qq.com/fcg-bin/cgi_get_portrait.fcg?uins=[QQ ID Number]
  • KRBanker (Blackmoon) uses the KaiXin exploit kit to deliver payloads via CVE-2015-3133 (Adobe Flash) through malicious JavaScript on compromised websites or advertisements.
  • KRBanker uses Process Hollowing to inject malicious code into a clean PE file from the System directory — monitor for suspicious child processes spawned from legitimate Windows system executables with anomalous network activity.
  • Detect KRBanker pharming setup by monitoring for creation or modification of the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL pointing to 127.0.0.1.
  • KRBanker resolves its pharming C2 IP by querying the QZone API (users.qzone.qq.com) and parsing the 'nickname' field — monitor for unusual outbound HTTP requests to this endpoint from non-browser processes.
  • KRBanker registers infected hosts to C2 via HTTP GET to /ca.php with MAC address and code page parameters — monitor for HTTP GET requests matching this URI pattern to external IPs.
  • ·The pharming C2 IP (23.107.204.38) is an example extracted from a QZone profile nickname field and may rotate frequently — over 200+ pharming server addresses were identified in 6 months.
  • ·The AutoConfigURL registry value uses random port and path components, making static string matching insufficient — pattern-based detection on 127.0.0.1 as proxy is required.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.