CVE-2015-8651
published 2015-12-28CVE-2015-8651: Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR…
PriorityP191high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-06-15
Exploited in the wild
EPSS
67.92%
99.2th percentile
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | < 20.0.0.233 | 20.0.0.233 |
| adobe | air_sdk | < 20.0.0.233 | 20.0.0.233 |
| adobe | air_sdk_compiler | < 20.0.0.233 | 20.0.0.233 |
| adobe | flash_player | < 11.2.202.559 | 11.2.202.559 |
| adobe | flash_player | < 18.0.0.324 | 18.0.0.324 |
| adobe | flash_player | >= 19.0.0.185 < 20.0.0.267 | 20.0.0.267 |
| hp | insight_control | < 7.6 | 7.6 |
| hp | insight_control_server_provisioning | < 7.6 | 7.6 |
| hp | matrix_operating_environment | — | — |
| hp | system_management_homepage | < 7.6 | 7.6 |
| hp | systems_insight_manager | < 7.6 | 7.6 |
| hp | version_control_repository_manager | < 7.6 | 7.6 |
| opensuse | evergreen | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_workstation_extension | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2015-8651 is actively exploited in the wild by multiple exploit kits including Rig, Astrum, Angler, and Neutrino — prioritize patching Adobe Flash Player before 18.0.0.324 and 20.x before 20.0.0.267 ↗
- →CVE-2015-8651 was found embedded in the Neutrino exploit kit; monitor for Neutrino EK traffic patterns delivering Flash exploits ↗
- →CVE-2015-8651 exploitation was initially limited to targeted attacks (zero-day); treat any exploitation as high-priority incident ↗
- →CVE-2015-8651 is associated with NanoLocker ransomware as a payload; detections of this Flash exploit should trigger hunting for NanoLocker indicators ↗
- →CVE-2015-8651 is leveraged by both Angler and Neutrino exploit kits; correlate EK landing page traffic with Flash exploit delivery ↗
- ·The Adobe security bulletin for this fix is APSB16-01 (not APSB15-33 as would normally be expected), because it was the planned January 2016 update released early due to active exploitation ↗
- ·Affected versions span Windows, OS X, and Linux platforms as well as Adobe AIR and AIR SDK; ensure all variants are covered in patch scope ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Adobe Flash Player Integer Overflow Vulnerability
cisa·2022-05-25·CVSS 8.8
CVE-2015-8651 [HIGH] CWE-189 Adobe Flash Player Integer Overflow Vulnerability
Vulnerability: Adobe Flash Player Integer Overflow Vulnerability
Affected: Adobe Flash Player
Integer overflow in Adobe Flash Player allows attackers to execute code.
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-8651
Remediation Due Date: 2022-06-15
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-01
vendor_redhat·2015-12-28·CVSS 8.8
CVE-2015-8651 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.
VulDB
Adobe Flash Player up to 18.0.0.268 numeric error (RHSA-2015:2697 / Nessus ID 87656)
vuldb·2026-04-23·CVSS 8.8
CVE-2015-8651 [HIGH] Adobe Flash Player up to 18.0.0.268 numeric error (RHSA-2015:2697 / Nessus ID 87656)
A vulnerability was found in Adobe Flash Player. It has been classified as critical. This affects an unknown function. This manipulation causes numeric error.
This vulnerability is registered as CVE-2015-8651. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-8p63-f9jh-3gch: Integer overflow in Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17
CVE-2015-8651 [HIGH] CWE-190 GHSA-8p63-f9jh-3gch: Integer overflow in Adobe Flash Player before 18
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.
OSV
CVE-2015-8651: Integer overflow in Adobe Flash Player before 18
osv·2015-12-28·CVSS 8.8
CVE-2015-8651 [HIGH] CVE-2015-8651: Integer overflow in Adobe Flash Player before 18
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.
VulnCheck
Adobe Flash Player Integer Overflow Vulnerability
vulncheck·2015·CVSS 8.8
CVE-2015-8651 [HIGH] CWE-189 Adobe Flash Player Integer Overflow Vulnerability
Adobe Flash Player Integer Overflow Vulnerability
Integer overflow in Adobe Flash Player allows attackers to execute code.
Affected: Adobe Flash Player
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Known Ransomware Campaign Use: Known
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://web.archive.org/web/20160104165148/http://drops.wooyun.org/tips/11726; https://www.forcepoint.com/blog/x-labs/missmalini-celebrity-site-awards-admedia-gate-angler-exploit-kit-during-oscars; https://www.welivesecurity.com/2016/12/06/readers-popular-websites-targeted-stealthy-stegano-exploit-kit-hiding-pixels-malicious-ads/; https://us-cert.cisa.gov/ncas/alerts/TA17-164A; https://cisa.
No detection rules found.
No public exploits indexed.
Qualys
The Rise of Ransomware
blogs_qualys·2021-10-05
The Rise of Ransomware
## Table of Contents
Ransomware Infection Vectors
Ransomware Attacks and Exact CVEs To Prioritize for Monitoring
Unified View of Critical Ransomware Risk Exposures
Qualys Ransomware Risk Assessment & Remediation Service
Continuous detection & prioritization for Ransomware-specific vulnerabilities withVMDR
DiscoverandPrioritizeRansomware Vulnerabilities
Discover and Mitigate RansomwareMisconfigurationssuch as SMB, Insecure RDP
Automated Proactive & Reactive Patching for Ransomware vulnerabilities
Ready to Learn more and see for yourself?
Resources
References
With most employees still working from remote locations, ransomware attacks have increased steadily since the early months of the Covid-19 pandemic. According to the FBI’s 2020 Internet Crime Report 2400+ ransomware-related
Trendmicro
Rig Abuses CVE-2018-8174 to Deliver Monero Miner
blogs_trendmicro·2018-05-31·CVSS 8.8
CVE-2018-8174 [HIGH] Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Exploits & Vulnerabilities
## Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Sometime around February to March last year, we saw the Rig exploit kit’s Seamless campaign adding another gate before the actual landing page.
By: Miguel Carlo Ang, Martin Co, Michael Villanueva 2018/05/31 Read time: ( words)
Save to Folio
An exploit kit such as Rig usually starts off with a threat actor compromising a website to inject a malicious script/code that eventually redirects would-be victims to the exploit kit’s landing page. Sometime around February to March last year, however, we saw Rig’s Seamless campaign adding another layer or gate before the actual landing page.
Along with updates in code, we also observed Rig integrating a cryptocurrency-mining malware as its final payload. Based on the
Trendmicro
Rig Abuses CVE-2018-8174 to Deliver Monero Miner
blogs_trendmicro·2018-05-31·CVSS 8.8
CVE-2018-8174 [HIGH] Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Exploits & Vulnerabilities
## Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Sometime around February to March last year, we saw the Rig exploit kit’s Seamless campaign adding another gate before the actual landing page.
By: Miguel Carlo Ang, Martin Co, Michael Villanueva May 31, 2018 Read time: ( words)
Save to Folio
An exploit kit such as Rig usually starts off with a threat actor compromising a website to inject a malicious script/code that eventually redirects would-be victims to the exploit kit’s landing page. Sometime around February to March last year, however, we saw Rig’s Seamless campaign adding another layer or gate before the actual landing page.
Along with updates in code, we also observed Rig integrating a cryptocurrency-mining malware as its final payload. Based on t
Trendmicro
Rig Abuses CVE-2018-8174 to Deliver Monero Miner
blogs_trendmicro·2018-05-31·CVSS 8.8
CVE-2018-8174 [HIGH] Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Exploits y vulnerabilidades
## Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Sometime around February to March last year, we saw the Rig exploit kit’s Seamless campaign adding another gate before the actual landing page.
By: Miguel Carlo Ang, Martin Co, Michael Villanueva May 31, 2018 Read time: ( words)
Save to Folio
An exploit kit such as Rig usually starts off with a threat actor compromising a website to inject a malicious script/code that eventually redirects would-be victims to the exploit kit’s landing page. Sometime around February to March last year, however, we saw Rig’s Seamless campaign adding another layer or gate before the actual landing page.
Along with updates in code, we also observed Rig integrating a cryptocurrency-mining malware as its final payload. Based on
Trendmicro
Rig Abuses CVE-2018-8174 to Deliver Monero Miner
blogs_trendmicro·2018-05-31·CVSS 8.8
CVE-2018-8174 [HIGH] Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Exploits & Vulnerabilities
## Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Sometime around February to March last year, we saw the Rig exploit kit’s Seamless campaign adding another gate before the actual landing page.
By: Miguel Carlo Ang, Martin Co, Michael Villanueva May 31, 2018 Read time: ( words)
Save to Folio
An exploit kit such as Rig usually starts off with a threat actor compromising a website to inject a malicious script/code that eventually redirects would-be victims to the exploit kit’s landing page. Sometime around February to March last year, however, we saw Rig’s Seamless campaign adding another layer or gate before the actual landing page.
Along with updates in code, we also observed Rig integrating a cryptocurrency-mining malware as its final payload. Based on t
Trendmicro
Rig Abuses CVE-2018-8174 to Deliver Monero Miner
blogs_trendmicro·2018-05-31·CVSS 8.8
CVE-2018-8174 [HIGH] Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Exploits & Vulnerabilities
# Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Sometime around February to March last year, we saw the Rig exploit kit’s Seamless campaign adding another gate before the actual landing page.
By: Miguel Carlo Ang, Martin Co, Michael Villanueva
2018/05/31
Read time: ( words)
Save to Folio
An exploit kit such as Rig usually starts off with a threat actor compromising a website to inject a malicious script/code that eventually redirects would-be victims to the exploit kit’s landing page. Sometime around February to March last year, however, we saw Rig’s Seamless campaign adding another layer or gate before the actual landing page.
Along with updates in code, we also observed Rig integrating a cryptocurrency-mining malware as its final payload. Based on the
Trendmicro
Rig Abuses CVE-2018-8174 to Deliver Monero Miner
blogs_trendmicro·2018-05-31·CVSS 8.8
CVE-2018-8174 [HIGH] Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Ausnutzung von Schwachstellen
## Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Sometime around February to March last year, we saw the Rig exploit kit’s Seamless campaign adding another gate before the actual landing page.
By: Miguel Carlo Ang, Martin Co, Michael Villanueva May 31, 2018 Read time: ( words)
Save to Folio
An exploit kit such as Rig usually starts off with a threat actor compromising a website to inject a malicious script/code that eventually redirects would-be victims to the exploit kit’s landing page. Sometime around February to March last year, however, we saw Rig’s Seamless campaign adding another layer or gate before the actual landing page.
Along with updates in code, we also observed Rig integrating a cryptocurrency-mining malware as its final payload. Based o
Zscaler
Top Exploit Kit Activity Roundup - Summer 2017 | Zscaler
blogs_zscaler·2017-09-12
Top Exploit Kit Activity Roundup - Summer 2017 | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Trendmicro
RATANKBA: Delving into Large-scale Watering Holes
blogs_trendmicro·2017-02-27
RATANKBA: Delving into Large-scale Watering Holes
Malware
## RATANKBA: Delving into Large-scale Watering Holes
We provide further analysis and insights regarding the RATANKBA malware, which was tied to malware attacks against banks in Poland, but also in a string of similar incidents involving financial institutions in different countries.
By: Trend Micro 2017/02/27 Read time: ( words)
Save to Folio
In early February, several financial organizations reported malware infection on their workstations, apparently coming from legitimate websites. The attacks turned out to be part of a large-scale campaign to compromise trusted websites in order to infect the systems of targeted enterprises across various industries. The strategy is typically known as a “ watering hole ” attack.
It was all sparked by a spate of recent malware attacks on P
Trendmicro
RATANKBA: Delving into Large-scale Watering Holes
blogs_trendmicro·2017-02-27
RATANKBA: Delving into Large-scale Watering Holes
Malware
# RATANKBA: Delving into Large-scale Watering Holes
We provide further analysis and insights regarding the RATANKBA malware, which was tied to malware attacks against banks in Poland, but also in a string of similar incidents involving financial institutions in different countries.
By: Trend Micro
2017/02/27
Read time: ( words)
Save to Folio
In early February, several financial organizations reported malware infection on their workstations, apparently coming from legitimate websites. The attacks turned out to be part of a large-scale campaign to compromise trusted websites in order to infect the systems of targeted enterprises across various industries. The strategy is typically known as a “watering hole” attack.
It was all sparked by a spate of recent malware attacks on Pol
Trendmicro
RATANKBA: Delving into Large-scale Watering Holes
blogs_trendmicro·2017-02-27
RATANKBA: Delving into Large-scale Watering Holes
Malware
## RATANKBA: Delving into Large-scale Watering Holes
We provide further analysis and insights regarding the RATANKBA malware, which was tied to malware attacks against banks in Poland, but also in a string of similar incidents involving financial institutions in different countries.
By: Trend Micro Feb 27, 2017 Read time: ( words)
Save to Folio
In early February, several financial organizations reported malware infection on their workstations, apparently coming from legitimate websites. The attacks turned out to be part of a large-scale campaign to compromise trusted websites in order to infect the systems of targeted enterprises across various industries. The strategy is typically known as a “ watering hole ” attack.
It was all sparked by a spate of recent malware attacks on
Qualys
2016 Year-End Summary for Adobe and Another 0-day Fix in December
blogs_qualys·2016-12-14·CVSS 8.8
CVE-2016-7892 [HIGH] 2016 Year-End Summary for Adobe and Another 0-day Fix in December
Adobe released nine security bulletins today in the December Security updates. The most notable update was APSB16-39 for Flash which fixed a 0-day vulnerability with exploits in the wild that is being used in targeted attacks. Adobe products including Flash and Acrobat PDF reader have long being targeted by exploit kits. In addition to the 0-day (CVE-2016-7892), 17 other vulnerabilities were fixed in Flash. This update address critical vulnerabilities that could potentially allow an attacker to take control of the affected system. Other updates included in today’s release fixed Coldfusion ( APSB16-44 ) , Robohelp ( APSB16-46 ), Adobe Digital Editions ( APSB16-45 ), InDesign ( APSB16-43 ) , Experience Manager ( APSB16-42 ) , DNG Converter ( APSB16-41 ) and Animate ( APSB16-38 ).
In 2016 Ad
Qualys
2016 Year-End Summary for Adobe and Another 0-day Fix in December | Qualys
blogs_qualys·2016-12-14·CVSS 8.8
CVE-2016-7892 [HIGH] 2016 Year-End Summary for Adobe and Another 0-day Fix in December | Qualys
Adobe released nine security bulletins today in the December Security updates. The most notable update was APSB16-39 for Flash which fixed a 0-day vulnerability with exploits in the wild that is being used in targeted attacks. Adobe products including Flash and Acrobat PDF reader have long being targeted by exploit kits. In addition to the 0-day (CVE-2016-7892), 17 other vulnerabilities were fixed in Flash. This update address critical vulnerabilities that could potentially allow an attacker to take control of the affected system. Other updates included in today’s release fixed Coldfusion (APSB16-44) , Robohelp (APSB16-46), Adobe Digital Editions (APSB16-45), InDesign (APSB16-43) , Experience Manager (APSB16-42) , DNG Converter (APSB16-41) and Animate (APSB16-38).
In 2016 Adobe vulnerabil
Fortinet
Java Browser Plugin is Dead, Long Live HTML5!
blogs_fortinet·2016-02-05
Java Browser Plugin is Dead, Long Live HTML5!
INDUSTRY TRENDS & INSIGHTS
Java Browser Plugin is Dead, Long Live HTML5!
By David Maciejak | February 05, 2016
Afew days ago, Oracle announced on their blog that they plan to kill the Java browser plugin in their next major version of JDK, scheduled for release in Q1 2017.
What does this mean? Should we worry about our browsing experience?
This really just means that it won’t be possible to run Java applets in the browser anymore. The infamous “applet” is a technology that was developed by Sun Microsystems in the 90’s and went on to be acquired by Oracle.
This technology was still popular in many exploit kits over the last two years but in the last year alone we saw a sudden shift where kits removed Java support in favor of embedding more Adobe Flash exploits and direct browser exploi
Qualys
Update: Last Adobe 0-day Patched for the Year | Qualys
blogs_qualys·2015-12-28·CVSS 8.8
CVE-2015-8651 [HIGH] Update: Last Adobe 0-day Patched for the Year | Qualys
Update : Qualys QID is 124421: Adobe Flash Player and AIR Security Update (APSB16-01).
Original : Adobe issued today their last update for 2015 for its Flash player. It addresses nineteen vulnerabilities and was released out of band because one of them (CVE-2015-8651) is under attack in the wild. At this point attacks are limited to special targets. The update is numbered APSB16-01 , not APSB15-33 as expected, most likely because it is basically the planned January 2016 update, anticipated due to the circumstances.
As with all 0-days fixes this one deserves special attention and a quick turnaround.
## Related content
Qualys
Update: Last Adobe 0-day Patched for the Year | Qualys
blogs_qualys·2015-12-28·CVSS 8.8
CVE-2015-8651 [HIGH] Update: Last Adobe 0-day Patched for the Year | Qualys
Update: Qualys QID is 124421: Adobe Flash Player and AIR Security Update (APSB16-01).
Original: Adobe issued today their last update for 2015 for its Flash player. It addresses nineteen vulnerabilities and was released out of band because one of them (CVE-2015-8651) is under attack in the wild. At this point attacks are limited to special targets. The update is numbered APSB16-01, not APSB15-33 as expected, most likely because it is basically the planned January 2016 update, anticipated due to the circumstances.
As with all 0-days fixes this one deserves special attention and a quick turnaround.
### Related
Krebs
Flash Player Patch Fixes 0-Day, 18 Other Flaws – Krebs on Security
blogs_krebs·2015-12-01·CVSS 8.8
CVE-2015-8651 [HIGH] Flash Player Patch Fixes 0-Day, 18 Other Flaws – Krebs on Security
Adobe has shipped a new version of its Flash Player browser plugin to close at least 19 security holes in the program, including one that is already being exploited in active attacks.
The new Flash version, v. 20.0.0.267 for most Mac and Windows users, includes a fix for a vulnerability (CVE-2015-8651) that Adobe says is being used in “limited, targeted attacks.” If you have Flash installed, please update it.
Better yet, get rid of Flash altogether, or at least disable it until and unless you need it. Doing without Flash just makes good security sense, and it isn’t as difficult as you might think: See my post, A Month Without Adobe Flash Player , for tips on how to minimize the risks of having Flash installed.
The most recent versions of Flash should be available from the Flash home pag
Recorded Future
How Analysts Can Deep Dive Into CVE Vulnerabilities
blogs_recorded_future·CVSS 8.8
[HIGH] How Analysts Can Deep Dive Into CVE Vulnerabilities
# How Analysts Can Deep Dive Into CVE Vulnerabilities
Patch management is a crucial part of information security, but the volume of patches can be difficult to manage. Many vulnerability managers need to oversee hundreds or even thousands of devices and ensure there are no weak spots that can be exploited.
The key to avoiding information overload is prioritization. But how can vulnerability managers keep the most critical threats top of mind?
Generally speaking, vulnerability management teams prioritize patching efforts based on CVSS scoring which incorporates many factors, including:
- The severity of the threat (the likelihood of it impacting your company and to what degree).
- The level of vulnerability (e.g., is the threat local or remote?).
- The cost of mitigation and/or recovery
Zscaler
Zscaler discovers Flash Player Vulnerabilities | 12-29-2015
blogs_zscaler
Zscaler discovers Flash Player Vulnerabilities | 12-29-2015
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Threat Intel
Darkhotel (Darkhotel, DUBNIUM, Zigzag Hail)
threat_intel·CVSS 8.8
[HIGH] Darkhotel (Darkhotel, DUBNIUM, Zigzag Hail)
# Threat Actor Profile: Darkhotel
ATT&CK ID: G0012
Also known as: Darkhotel, DUBNIUM, Zigzag Hail
Suspected origin: South Korea
## Overview
Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.(Citation: Kaspersky Darkhotel)(Citation: Securelist Darkhotel Aug 2015)(Citation: Microsoft Digital Defense FY20 Sept 2020)
## Techniques (TTPs)
### Initial Access
- T1566.001 Spearphishing Attachment
Usage: Darkhotel has sent spearphishing emails with malicious RAR
Recorded Future
How Analysts Can Deep Dive Into CVE Vulnerabilities | Recorded Future
blogs_recorded_future·CVSS 8.8
[HIGH] How Analysts Can Deep Dive Into CVE Vulnerabilities | Recorded Future
## How Analysts Can Deep Dive Into CVE Vulnerabilities
Patch management is a crucial part of information security, but the volume of patches can be difficult to manage. Many vulnerability managers need to oversee hundreds or even thousands of devices and ensure there are no weak spots that can be exploited.
The key to avoiding information overload is prioritization. But how can vulnerability managers keep the most critical threats top of mind?
Generally speaking, vulnerability management teams prioritize patching efforts based on CVSS scoring which incorporates many factors, including :
The severity of the threat (the likelihood of it impacting your company and to what degree).
The level of vulnerability (e.g., is the threat local or remote?).
The cost of mitigation and/or recovery.
arXiv
Hesperus is Phosphorus: Mapping Threat Actor Naming Taxonomies at Scale
arxiv_fulltext·2025-11-30
Hesperus is Phosphorus: Mapping Threat Actor Naming Taxonomies at Scale
1
.001
Hesperus is Phosphorus
Roa, Suarez, and Tapiador
[mode = title]Hesperus is Phosphorus: Mapping Threat Actor Naming Taxonomies at Scale
[1]
[1]
This research was supported by MICIU/AEI/10.13039/501100011033 under Grant
No. PID2022-140126OB-I00 (CYCAD) and INCIBE under Grant APAMCiber. The opinions, findings, and conclusions or recommendations expressed are those of the authors and do not necessarily reflect those of any of the funding agencies.
Gonzalo Roa
[email protected]
Data curation, Methodology, Software, Analysis, Writing, Visualization
Manuel Suarez-Roman[orcid=0009-0008-2569-6178]
[email protected]
Data curation, Methodology, Software, Analysis, Writing, Visualization
Juan Tapiador[orcid=0000-0002-4573-3967]
[email protected]
Conceptualization, Methodolo
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-01
bugzilla·2015-12-29·CVSS 10.0
CVE-2015-8644 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB16-01
flash-plugin: multiple code execution issues fixed in APSB16-01
Adobe Security Bulletin APSB16-01 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB16-01:
These updates resolve a type confusion vulnerability that could lead to code execution (CVE-2015-8644).
These updates resolve an integer overflow vulnerability that could lead to code execution (CVE-2015-8651).
These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, CVE-2015-8650).
These updates resolv
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00048.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2697.htmlhttp://www.securityfocus.com/bid/79705http://www.securitytracker.com/id/1034544https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://helpx.adobe.com/security/products/flash-player/apsb16-01.htmlhttps://security.gentoo.org/glsa/201601-03http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00048.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2697.htmlhttp://www.securityfocus.com/bid/79705http://www.securitytracker.com/id/1034544https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://helpx.adobe.com/security/products/flash-player/apsb16-01.htmlhttps://security.gentoo.org/glsa/201601-03https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-8651
2015-12-28
Published
2022-05-25
Added to CISA KEV
Exploited in the wild