CVE-2016-0189
published 2016-05-11CVE-2016-0189: The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to…
PriorityP190high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-04-18
Exploited in the wild
EPSS
93.16%
99.8th percentile
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | jscript | — | — |
| microsoft | vbscript | — | — |
| microsoft | vbscript | — | — |
| msrc | internet_explorer_10 | — | — |
| msrc | internet_explorer_10_on_windows_server_2012 | — | — |
| msrc | internet_explorer_11 | — | — |
| msrc | internet_explorer_11_on_windows_10_for_32-bit_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_for_x64-based_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1511_for_32-bit_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1511_for_x64-based_systems | — | — |
| msrc | internet_explorer_11_on_windows_7_for_32-bit_systems_service_pack_1 | — | — |
| msrc | internet_explorer_11_on_windows_7_for_x64-based_systems_service_pack_1 | — | — |
| msrc | internet_explorer_11_on_windows_8.1_for_32-bit_systems | — | — |
| msrc | internet_explorer_11_on_windows_8.1_for_x64-based_systems | — | — |
| msrc | internet_explorer_11_on_windows_rt_8.1 | — | — |
| msrc | internet_explorer_11_on_windows_server_2008_r2_for_x64-based_systems_service_pac | — | — |
| msrc | internet_explorer_11_on_windows_server_2012_r2 | — | — |
| msrc | internet_explorer_9 | — | — |
| msrc | internet_explorer_9_on_windows_server_2008_for_32-bit_systems_service_pack_2 | — | — |
| msrc | internet_explorer_9_on_windows_server_2008_for_x64-based_systems_service_pack_2 | — | — |
| msrc | internet_explorer_9_on_windows_vista_service_pack_2 | — | — |
| msrc | internet_explorer_9_on_windows_vista_x64_edition_service_pack_2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2016-0189 exploit technique involves modifying the SafeMode flag in the VBScript Engine to obtain execution permission from Shell.Application and run shellcode ↗
- →Terror EK uses cookie detection to prevent repeated exploit site visits; monitor for exploit kit cookie-based fingerprinting behavior ↗
- →CVE-2016-0189 was rapidly adopted by Sundown EK in July 2016; monitor for Sundown EK traffic patterns targeting IE users ↗
- →Smoke Loader downloader Trojan is the malware payload delivered via Terror EK campaigns exploiting CVE-2016-0189 ↗
- →Terror EK SWF payloads are protected with 'DComSoft SWF protector' to evade decompiler-based detection ↗
- →For Vista and Windows Server 2008, CVE-2016-0189 is patched separately via MS16-053 (JScript/VBScript package), not just MS16-051 (IE); ensure both patches are applied ↗
- ·CVE-2016-0189 affects JScript 5.8 and VBScript 5.7/5.8 as used in Internet Explorer 9 through 11; patched by MS16-051 (IE) and MS16-053 (standalone JScript/VBScript for Vista/Server 2008) ↗
- ·CVE-2016-0189 exploit does not work on systems with updated Internet Explorer versions; patching IE is the primary mitigation ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vulncheck7.5HIGH
cisa7.5HIGH
vendor_msrc7.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Internet Explorer Memory Corruption Vulnerability
cisa·2022-03-28·CVSS 7.5
CVE-2016-0189 [HIGH] CWE-119 Microsoft Internet Explorer Memory Corruption Vulnerability
Vulnerability: Microsoft Internet Explorer Memory Corruption Vulnerability
Affected: Microsoft Internet Explorer
The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-0189
Remediation Due Date: 2022-04-18
Microsoft
Scripting Engine Memory Corruption Vulnerability
vendor_msrc·2016-05-10·CVSS 7.5
CVE-2016-0189 [HIGH] Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted websi
Microsoft
Scripting Engine Memory Corruption Vulnerability
vendor_msrc·2016-05-10·CVSS 7.5
CVE-2016-0187 [HIGH] Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted websi
VulDB
Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption (MS16-053 / EDB-40118)
vuldb·2026-04-23·CVSS 7.5
CVE-2016-0189 [HIGH] Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption (MS16-053 / EDB-40118)
A vulnerability categorized as critical has been discovered in Microsoft Windows Server 2008/Vista SP2. This affects an unknown part of the component JScript/VBScript. The manipulation results in memory corruption.
This vulnerability is cataloged as CVE-2016-0189. The attack may be launched remotely. Furthermore, there is an exploit available.
Applying a patch is advised to resolve this issue.
VulDB
Microsoft Internet Explorer 9/10/11 Scripting Engine memory corruption (MS16-051 / EDB-40118)
vuldb·2026-04-23·CVSS 7.5
CVE-2016-0189 [HIGH] Microsoft Internet Explorer 9/10/11 Scripting Engine memory corruption (MS16-051 / EDB-40118)
A vulnerability classified as critical was found in Microsoft Internet Explorer 9/10/11. Impacted is an unknown function of the component Scripting Engine. Executing a manipulation can lead to memory corruption.
This vulnerability is handled as CVE-2016-0189. The attack can be executed remotely. Additionally, an exploit exists.
Applying a patch is advised to resolve this issue.
GHSA
GHSA-qw68-vqp7-ff9r: The Microsoft (1) JScript 5
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2016-0189 [HIGH] CWE-119 GHSA-qw68-vqp7-ff9r: The Microsoft (1) JScript 5
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.
GHSA
GHSA-9c63-jjgp-f84c: The Microsoft (1) JScript 5
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2016-0187 [HIGH] CWE-119 GHSA-9c63-jjgp-f84c: The Microsoft (1) JScript 5
The Microsoft (1) JScript 5.8 and (2) VBScript 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0189.
VulnCheck
Microsoft Internet Explorer Memory Corruption Vulnerability
vulncheck·2016·CVSS 7.5
CVE-2016-0189 [HIGH] CWE-119 Microsoft Internet Explorer Memory Corruption Vulnerability
Microsoft Internet Explorer Memory Corruption Vulnerability
The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
Affected: Microsoft Internet Explorer
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2016-May; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.forcepoint.com/blog/x-labs/highly-evasive-code-injection-awaits-user-interaction-delivering-malware; https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/terror-exploit-kit-more-like-error-exploit-kit/; htt
Suricata
ET EXPLOIT CVE-2016-0189 Exploit HFS Actor
suricata·2017-09-07·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT CVE-2016-0189 Exploit HFS Actor
ET EXPLOIT CVE-2016-0189 Exploit HFS Actor
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT CVE-2016-0189 Exploit HFS Actor"; flow:established,to_client; http.server; content:"HFS"; startswith; file.data; content:"triggerBug"; nocase; fast_pattern; content:"exploit"; nocase; content:"intToStr"; nocase; content:"strToInt"; nocase; classtype:trojan-activity; sid:2024677; rev:4; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2017_09_07, cve CVE_2016_0189, deployment Perimeter, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT CVE-2016-0189 Exploit
suricata·2017-09-07·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT CVE-2016-0189 Exploit
ET EXPLOIT CVE-2016-0189 Exploit
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT CVE-2016-0189 Exploit"; flow:established,to_client; file.data; content:"triggerBug"; nocase; fast_pattern; pcre:"/^\s*(?:\x28|\%28)/Rs"; content:"exploit"; nocase; pcre:"/^\s*(?:\x28|\%28)o/Rs"; content:"intToStr"; nocase; pcre:"/^\s*(?:\x28|\%28)x/Rs"; content:"strToInt"; nocase; pcre:"/^\s*(?:\x28|\%28)s/Rs"; classtype:trojan-activity; sid:2024676; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2017_09_07, cve CVE_2016_0189, deployment Perimeter, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT_KIT Terror EK CVE-2016-0189 Exploit
suricata·2017-04-04·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT_KIT Terror EK CVE-2016-0189 Exploit
ET EXPLOIT_KIT Terror EK CVE-2016-0189 Exploit
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT Terror EK CVE-2016-0189 Exploit"; flow:established,to_client; file.data; content:"dllcode"; nocase; fast_pattern; content:"|28 26 68 34 64 2c 26 68 35 61 2c 26 68 38 30 2c 30 2c 31 2c 30 2c 30 2c 30|"; nocase; content:"GetSpecialFolder"; nocase; reference:cve,2016-0189; classtype:exploit-kit; sid:2024168; rev:4; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2017_04_04, cve CVE_2016_0189, deployment Perimeter, malware_family Exploit_Kit_Terror, performance_impact Low, confidence High, signature_severity Major, tag Exploit_Kit_Terror, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT_KIT Terror EK CVE-2015-2419 Exploit
suricata·2017-04-04·CVSS 8.8
CVE-2016-0189 [HIGH] ET EXPLOIT_KIT Terror EK CVE-2015-2419 Exploit
ET EXPLOIT_KIT Terror EK CVE-2015-2419 Exploit
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT Terror EK CVE-2015-2419 Exploit"; flow:established,to_client; file.data; content:"EB125831C966B9"; nocase; content:"05498034088485C975F7FFE0E8E9FFFFFFD10D61074028D7D5D3B544E0"; distance:2; within:58; nocase; reference:cve,2016-0189; classtype:exploit-kit; sid:2024170; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2017_04_04, cve CVE_2016_0189, deployment Perimeter, malware_family Exploit_Kit_Terror, performance_impact Low, confidence High, signature_severity Major, tag Exploit_Kit_Terror, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT_KIT Terror EK CVE-2016-0189 Exploit M2
suricata·2017-04-04·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT_KIT Terror EK CVE-2016-0189 Exploit M2
ET EXPLOIT_KIT Terror EK CVE-2016-0189 Exploit M2
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT Terror EK CVE-2016-0189 Exploit M2"; flow:established,to_client; file.data; content:"|73 74 72 54 6f 49 6e 74 28 4d 69 64 28 6d 65 6d 2c 20 31 2c 20 32 29 29|"; content:"|2b 20 26 48 31 37 34|"; reference:cve,2016-0189; classtype:exploit-kit; sid:2024169; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2017_04_04, cve CVE_2016_0189, deployment Perimeter, malware_family Exploit_Kit_Terror, performance_impact Low, confidence High, signature_severity Major, tag Exploit_Kit_Terror, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT_KIT SunDown EK CVE-2016-0189 Sep 22 2016 (b643)
suricata·2016-09-22·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT_KIT SunDown EK CVE-2016-0189 Sep 22 2016 (b643)
ET EXPLOIT_KIT SunDown EK CVE-2016-0189 Sep 22 2016 (b643)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT SunDown EK CVE-2016-0189 Sep 22 2016 (b643)"; flow:established,to_client; flowbits:set,SunDown.EK; file.data; content:"hADUiGDEgPTUbAa"; classtype:exploit-kit; sid:2023282; rev:5; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2016_09_22, cve CVE_2016_0189, deployment Perimeter, malware_family SunDown, confidence High, signature_severity Major, tag Exploit_Kit_Sundown, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b646)
suricata·2016-09-12·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b646)
ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b646)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b646)"; flow:established,to_client; file.data; content:"wcmVmaXggJiAiJXUwMDE2JXU0MTQxJXU0MTQxJXU0MTQxJXU0MjQyJXU0MjQyI"; classtype:exploit-kit; sid:2023195; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2016_09_12, cve CVE_2016_0189, deployment Perimeter, malware_family SunDown, malware_family RIG, confidence High, signature_severity Major, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b645)
suricata·2016-09-12·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b645)
ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b645)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b645)"; flow:established,to_client; file.data; content:"ByZWZpeCAmICIldTAwMTYldTQxNDEldTQxNDEldTQxNDEldTQyNDIldTQyNDIi"; classtype:exploit-kit; sid:2023194; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2016_09_12, cve CVE_2016_0189, deployment Perimeter, malware_family SunDown, malware_family RIG, confidence High, signature_severity Major, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b641)
suricata·2016-09-12·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b641)
ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b641)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b641)"; flow:established,to_client; file.data; content:"RnVuY3Rpb24gbGVha01lbS"; classtype:exploit-kit; sid:2023190; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2016_09_12, cve CVE_2016_0189, deployment Perimeter, malware_family SunDown, malware_family RIG, confidence High, signature_severity Major, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b643)
suricata·2016-09-12·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b643)
ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b643)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b643)"; flow:established,to_client; file.data; content:"GdW5jdGlvbiBsZWFrTWVtI"; classtype:exploit-kit; sid:2023192; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2016_09_12, cve CVE_2016_0189, deployment Perimeter, malware_family SunDown, malware_family RIG, confidence High, signature_severity Major, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b642)
suricata·2016-09-12·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b642)
ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b642)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b642)"; flow:established,to_client; file.data; content:"Z1bmN0aW9uIGxlYWtNZW0g"; classtype:exploit-kit; sid:2023191; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2016_09_12, cve CVE_2016_0189, deployment Perimeter, malware_family SunDown, malware_family RIG, confidence High, signature_severity Major, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b644)
suricata·2016-09-12·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b644)
ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b644)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT CVE-2016-0189 Exploit as Observed in Sundown/RIG EK (b644)"; flow:established,to_client; file.data; content:"cHJlZml4ICYgIiV1MDAxNiV1NDE0MSV1NDE0MSV1NDE0MSV1NDI0MiV1NDI0Mi"; classtype:exploit-kit; sid:2023193; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2016_09_12, cve CVE_2016_0189, deployment Perimeter, malware_family SunDown, malware_family RIG, confidence High, signature_severity Major, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT CVE-2016-0189 Common Construct M2
suricata·2016-07-15·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT CVE-2016-0189 Common Construct M2
ET EXPLOIT CVE-2016-0189 Common Construct M2
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT CVE-2016-0189 Common Construct M2"; flow:established,to_client; file.data; content:"triggerBug"; nocase; content:"Dim "; nocase; distance:0; content:".resize"; nocase; pcre:"/^\s*\x28/Rs"; content:"Mid"; pcre:"/^\s*?\(x\s*,\s*1,\s*24000\s*\x29/Rs"; reference:url,theori.io/research/cve-2016-0189; reference:cve,2016-0189; classtype:attempted-user; sid:2022972; rev:4; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2016_07_15, cve CVE_2016_0189, deployment Perimeter, performance_impact Low, signature_severity Major, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT CVE-2016-0189 Common Construct M1
suricata·2016-07-15·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT CVE-2016-0189 Common Construct M1
ET EXPLOIT CVE-2016-0189 Common Construct M1
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT CVE-2016-0189 Common Construct M1"; flow:established,to_client; file.data; content:"%u0008%u4141%u4141%u4141"; nocase; content:"redim"; nocase; content:"Preserve"; content:"2000"; distance:0; pcre:"/^\s*?\x29/Rs"; content:"%u400C%u0000%u0000%u0000"; nocase; reference:url,theori.io/research/cve-2016-0189; reference:cve,2016-0189; classtype:attempted-user; sid:2022971; rev:4; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2016_07_15, cve CVE_2016_0189, deployment Perimeter, performance_impact Low, signature_severity Major, tag CVE_2016_0189, tag CISA_KEV, updated_at 2024_03_14;)
Exploit-DB
Microsoft Internet Explorer 11 (Windows 10) - VBScript Memory Corruption (MS16-051)
exploitdb·2016-06-22·CVSS 7.5
CVE-2016-0189 [HIGH] Microsoft Internet Explorer 11 (Windows 10) - VBScript Memory Corruption (MS16-051)
Microsoft Internet Explorer 11 (Windows 10) - VBScript Memory Corruption (MS16-051)
---
Source: https://github.com/theori-io/cve-2016-0189
# CVE-2016-0189
Proof-of-Concept exploit for CVE-2016-0189 (VBScript Memory Corruption in IE11)
Tested on Windows 10 IE11.
### Write-up
http://theori.io/research/cve-2016-0189
### To run
1. Download `support/*.dll` (or compile \*.cpp for yourself) and `exploit/*.html` to a directory.
2. Serve the directory using a webserver (or python's simple HTTP server).
3. Browse with a victim IE to `vbscript_bypass_pm.html`.
4. (Re-fresh or re-open in case it doesn't work; It's not 100% reliable.)
Exploit-DB Mirror: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/40118.zip
Metasploit
Internet Explorer 11 VBScript Engine Memory Corruption
metasploit·CVSS 7.5
CVE-2016-0189 [HIGH] Internet Explorer 11 VBScript Engine Memory Corruption
Internet Explorer 11 VBScript Engine Memory Corruption
This module exploits the memory corruption vulnerability (CVE-2016-0189) present in the VBScript engine of Internet Explorer 11.
Trendmicro
Magniber unter der Lupe
blogs_trendmicro·2023-02-02·CVSS 7.5
[HIGH] Magniber unter der Lupe
Ransomware
## Magniber unter der Lupe
Magniber-Ransomware nutzt verschiedene Schwachstellen aus, aber obwohl sie im Vergleich zu den neueren Ransomware-Kampagnen mit doppelter Erpressung eine einfachere Kill Chain verwendet, ist sie nicht weniger effektiv. Die Analyse zeigt, was zu tun ist.
By: Trend Micro Feb 02, 2023 Read time: ( words)
Save to Folio
Die Ransomware wurde bereits vor sechs Jahren entdeckt, dennoch verwenden Angreifer die Malware immer noch. Im Oktober 2022 gab es Berichte über Phishing-Attacken, über die Magniber-Ransomware verteilt wurde. Sie nutzten Standalone JavaScript-Dateien, die mit einem manipulierten Schlüssel digital signiert waren, und missbrauchten die Zero Day-Lücke CVE-2022-44698 , um Mark-of-the-Web (MOTW)-Sicherheitswarnungen zu umgehen. So konnten bö
Tenable
Cybersecurity Snapshot: 6 Things That Matter Right Now
blogs_tenable·2022-08-19
Cybersecurity Snapshot: 6 Things That Matter Right Now
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Analyzing the Vulnerabilities Associated with the Top Malware Strains of 2021
blogs_tenable·2022-08-04
Analyzing the Vulnerabilities Associated with the Top Malware Strains of 2021
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
New Campaign Sees LokiBot Delivered Via Multiple Methods
blogs_trendmicro·2021-08-25·CVSS 7.5
[HIGH] New Campaign Sees LokiBot Delivered Via Multiple Methods
Malware
## New Campaign Sees LokiBot Delivered Via Multiple Methods
We recently detected an aggressive malware distribution campaign delivering LokiBot via multiple techniques, including the exploitation of older vulnerabilities.
By: William Gamazo Sanchez, Bin Lin 2021/08/25 Read time: ( words)
Save to Folio
Although none of these techniques are particularly new, we want to build awareness about this campaign and encourage users to patch their systems as soon as possible if they are potentially affected.
When the document is opened, the user is presented the option to allow or block a connection to a specific host at “192[.]23[.]212[.]137”.
The URL is placed as an action in the PDF “OpenAction” directory, so a web visit is performed when the user opens the document.
If the user al
Trendmicro
New Campaign Sees LokiBot Delivered Via Multiple Methods
blogs_trendmicro·2021-08-25·CVSS 7.5
[HIGH] New Campaign Sees LokiBot Delivered Via Multiple Methods
Malware
## New Campaign Sees LokiBot Delivered Via Multiple Methods
We recently detected an aggressive malware distribution campaign delivering LokiBot via multiple techniques, including the exploitation of older vulnerabilities.
By: William Gamazo Sanchez, Bin Lin Aug 25, 2021 Read time: ( words)
Save to Folio
Although none of these techniques are particularly new, we want to build awareness about this campaign and encourage users to patch their systems as soon as possible if they are potentially affected.
When the document is opened, the user is presented the option to allow or block a connection to a specific host at “192[.]23[.]212[.]137”.
The URL is placed as an action in the PDF “OpenAction” directory, so a web visit is performed when the user opens the document.
If the user
Trendmicro
New Campaign Sees LokiBot Delivered Via Multiple Methods
blogs_trendmicro·2021-08-25·CVSS 7.5
[HIGH] New Campaign Sees LokiBot Delivered Via Multiple Methods
Malware
# New Campaign Sees LokiBot Delivered Via Multiple Methods
We recently detected an aggressive malware distribution campaign delivering LokiBot via multiple techniques, including the exploitation of older vulnerabilities.
By: William Gamazo Sanchez, Bin Lin
2021/08/25
Read time: ( words)
Save to Folio
# Introduction
We recently detected an aggressive malware distribution campaign delivering LokiBot via multiple techniques, including the exploitation of older vulnerabilities. This blog entry describes and provides an example of one the methods used in the campaign, as well as a short analysis of the payload. We found that one of the command-and-control (C&C) servers had enabled directory browsing, allowing us to retrieve updated samples.
Figure 1. C&C server with directory br
Unit42
Web-Based Threats: First Half 2019
blogs_unit42·2019-11-01
Web-Based Threats: First Half 2019
Threat Research Center
Trend Reports
Malware
## Web-Based Threats: First Half 2019
Fang Liu
Tao Yan
Jin Chen
Rongbo Shao
Zhanglin He
Bo Qu
Published: November 1, 2019
Malware
Trend Reports
Vulnerabilities
ELink
Exploit Kits
Malicious Domains
Malicious URL
Phishing
## Executive Summary
Our Unit 42 research team routinely evaluates the data from our Email Link Analysis (ELINK) system . In examining the data we collect, which includes URLs extracted from emails or submitted by API, we can identify patterns and trends which helps us discern prevalent web threats. This blog is the fifth installment in a series of posts tracking web-based threats over time, specifically, statistics pertaining to malicious URLs, domains, exploit kits, vulnerabilities, and phishing scams.
Unit42
Web-Based Threats: First Half 2019
blogs_unit42·2019-11-01
Web-Based Threats: First Half 2019
# Executive Summary
Our Unit 42 research team routinely evaluates the data from our Email Link Analysis (ELINK) system. In examining the data we collect, which includes URLs extracted from emails or submitted by API, we can identify patterns and trends which helps us discern prevalent web threats. This blog is the fifth installment in a series of posts tracking web-based threats over time, specifically, statistics pertaining to malicious URLs, domains, exploit kits, vulnerabilities, and phishing scams.
We observed a significant decrease in the activity of the Fallout exploit kit in the first quarter of 2019 while at the same time observing an increase in activity of the Kaixin exploit kit in the second quarter. Kaixin is primarily observed hosted in China and with the increased popularit
Zscaler
Exploit Kit Activity Roundup Spring 2019 | Zscaler Blog
blogs_zscaler·2019-05-31
Exploit Kit Activity Roundup Spring 2019 | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Unit42
Web-based Threats-2018 Q4: France Rises to #1 for Malicious URL Hosting, US #1 for Phishing
blogs_unit42·2019-05-30·CVSS 8.8
[HIGH] Web-based Threats-2018 Q4: France Rises to #1 for Malicious URL Hosting, US #1 for Phishing
Executive Summary
Our Unit 42 research team routinely evaluates the data from our Email Link Analysis (ELINK) system. In examining the data it collects, which are URLs extracted from emails or submitted by API, we can identify patterns and trends which help us discern prevalent web threats. This blog is the fourth (4th quarter of 2018) installment in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, CVEs, and now, phishing scams.
The key findings in this quarter’s report in summary are:
1. After Q4 saw an increase in malicious URLs, ending a trend of decreasing malicious URLs starting in Q1 and continuing through Q3.
2. For the first time in our tracking, the United States is not the number one
Unit42
Web-based Threats-2018 Q4: France Rises to #1 for Malicious URL Hosting, US #1 for Phishing
blogs_unit42·2019-05-30·CVSS 8.8
CVE-2018-8174 [HIGH] Web-based Threats-2018 Q4: France Rises to #1 for Malicious URL Hosting, US #1 for Phishing
Threat Research Center
Trend Reports
Malware
## Web-based Threats-2018 Q4: France Rises to #1 for Malicious URL Hosting, US #1 for Phishing
Bo Qu
Tao Yan
Rongbo Shao
Zhanglin He
Published: May 30, 2019
Malware
Trend Reports
Vulnerabilities
Azorult
CVE-2018-8174
ELink
Executive Summary
Our Unit 42 research team routinely evaluates the data from our Email Link Analysis (ELINK) system . In examining the data it collects, which are URLs extracted from emails or submitted by API, we can identify patterns and trends which help us discern prevalent web threats. This blog is the fourth (4th quarter of 2018) installment in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, CVEs, and now, ph
Zscaler
Top EK Activity Roundup – Winter 2019 | Zscaler Blog
blogs_zscaler·2019-01-18
Top EK Activity Roundup – Winter 2019 | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Unit42
Web-based Threats-2018 Q3: Malicious URLs and Domains take a Dip
blogs_unit42·2018-12-27·CVSS 9.8
[CRITICAL] Web-based Threats-2018 Q3: Malicious URLs and Domains take a Dip
# Executive Summary
Our Email Link Analysis (ELINK) system is routinely reviewed by our Unit 42 research team. In examining the data it collects, patterns and trends are discovered which helps us discern prevalent web threats. This blog is the third (3rd quarter of 2018) in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, and CVEs.
During Quarter 3 (Q3), July – September, a notable shift occurred with the malicious URL and domain data; there was a significant drop in the number of malicious URLs as well as a drop in malicious domains that will be discussed below. In addition, we will be covering an interesting malicious Flash SWF that exploits CVE-2015-5119.
# URLs
Based on our analysis of dat
Unit42
Web-based Threats-2018 Q3: Malicious URLs and Domains take a Dip
blogs_unit42·2018-12-27·CVSS 9.8
CVE-2015-5119 [CRITICAL] Web-based Threats-2018 Q3: Malicious URLs and Domains take a Dip
Threat Research Center
Trend Reports
Malware
## Web-based Threats-2018 Q3: Malicious URLs and Domains take a Dip
Bo Qu
Tao Yan
Rongbo Shao
Zhanglin He
Xingyu Jin
Published: December 27, 2018
Malware
Trend Reports
Vulnerabilities
CVE-2015-5119
ELink
## Executive Summary
Our Email Link Analysis (ELINK) system is routinely reviewed by our Unit 42 research team. In examining the data it collects, patterns and trends are discovered which helps us discern prevalent web threats. This blog is the third (3rd quarter of 2018) in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, and CVEs.
During Quarter 3 (Q3), July – September, a notable shift occurred with the malicious URL and domain d
Trendmicro
New CVE-2018-8373 Exploit Spotted
blogs_trendmicro·2018-09-25·CVSS 8.8
CVE-2018-8373 [HIGH] New CVE-2018-8373 Exploit Spotted
Exploits y vulnerabilidades
## New CVE-2018-8373 Exploit Spotted
On September 18, 2018, more than a month after we published a blog revealing the details of a use-after-free (UAF) vulnerability that affects the VBScript engine in newer Windows versions, we spotted another exploit that uses the same vulnerability.
By: Elliot Cao Sep 25, 2018 Read time: ( words)
Save to Folio
On September 18, 2018, more than a month after we published a blog revealing the details of a use-after-free (UAF) vulnerability CVE-2018-8373 that affects the VBScript engine in newer Windows versions, we spotted another exploit that uses the same vulnerability. It's important to note that this exploit doesn't work on systems with updated Internet Explorer versions.
Instead of modifying the CONTEXT structure of N
Trendmicro
New CVE-2018-8373 Exploit Spotted
blogs_trendmicro·2018-09-25·CVSS 8.8
CVE-2018-8373 [HIGH] New CVE-2018-8373 Exploit Spotted
Exploits & Vulnerabilities
## New CVE-2018-8373 Exploit Spotted
On September 18, 2018, more than a month after we published a blog revealing the details of a use-after-free (UAF) vulnerability that affects the VBScript engine in newer Windows versions, we spotted another exploit that uses the same vulnerability.
By: Elliot Cao 2018/09/25 Read time: ( words)
Save to Folio
On September 18, 2018, more than a month after we published a blog revealing the details of a use-after-free (UAF) vulnerability CVE-2018-8373 that affects the VBScript engine in newer Windows versions, we spotted another exploit that uses the same vulnerability. It's important to note that this exploit doesn't work on systems with updated Internet Explorer versions.
Instead of modifying the CONTEXT structure of NtCo
Trendmicro
New CVE-2018-8373 Exploit Spotted
blogs_trendmicro·2018-09-25·CVSS 8.8
CVE-2018-8373 [HIGH] New CVE-2018-8373 Exploit Spotted
Exploits & Vulnerabilities
## New CVE-2018-8373 Exploit Spotted
On September 18, 2018, more than a month after we published a blog revealing the details of a use-after-free (UAF) vulnerability that affects the VBScript engine in newer Windows versions, we spotted another exploit that uses the same vulnerability.
By: Elliot Cao Sep 25, 2018 Read time: ( words)
Save to Folio
On September 18, 2018, more than a month after we published a blog revealing the details of a use-after-free (UAF) vulnerability CVE-2018-8373 that affects the VBScript engine in newer Windows versions, we spotted another exploit that uses the same vulnerability. It's important to note that this exploit doesn't work on systems with updated Internet Explorer versions.
Instead of modifying the CONTEXT structure of Nt
Trendmicro
New CVE-2018-8373 Exploit Spotted
blogs_trendmicro·2018-09-25·CVSS 8.8
CVE-2018-8373 [HIGH] New CVE-2018-8373 Exploit Spotted
Ausnutzung von Schwachstellen
## New CVE-2018-8373 Exploit Spotted
On September 18, 2018, more than a month after we published a blog revealing the details of a use-after-free (UAF) vulnerability that affects the VBScript engine in newer Windows versions, we spotted another exploit that uses the same vulnerability.
By: Elliot Cao Sep 25, 2018 Read time: ( words)
Save to Folio
On September 18, 2018, more than a month after we published a blog revealing the details of a use-after-free (UAF) vulnerability CVE-2018-8373 that affects the VBScript engine in newer Windows versions, we spotted another exploit that uses the same vulnerability. It's important to note that this exploit doesn't work on systems with updated Internet Explorer versions.
Instead of modifying the CONTEXT structure of
Trendmicro
New CVE-2018-8373 Exploit Spotted
blogs_trendmicro·2018-09-25·CVSS 8.8
CVE-2018-8373 [HIGH] New CVE-2018-8373 Exploit Spotted
Exploits & Vulnerabilities
# New CVE-2018-8373 Exploit Spotted
On September 18, 2018, more than a month after we published a blog revealing the details of a use-after-free (UAF) vulnerability that affects the VBScript engine in newer Windows versions, we spotted another exploit that uses the same vulnerability.
By: Elliot Cao
2018/09/25
Read time: ( words)
Save to Folio
On September 18, 2018, more than a month after we published a blog revealing the details of a use-after-free (UAF) vulnerability CVE-2018-8373 that affects the VBScript engine in newer Windows versions, we spotted another exploit that uses the same vulnerability. It's important to note that this exploit doesn't work on systems with updated Internet Explorer versions.
Instead of modifying the CONTEXT structure of NtCo
Unit42
Web-based Threats-2018 Q2: U.S. Remains #1 in Malicious Web Addresses, China Falls from #2 to #7
blogs_unit42·2018-09-05·CVSS 7.5
CVE-2018-8174 [HIGH] Web-based Threats-2018 Q2: U.S. Remains #1 in Malicious Web Addresses, China Falls from #2 to #7
Threat Research Center
Trend Reports
Vulnerabilities
## Web-based Threats-2018 Q2: U.S. Remains #1 in Malicious Web Addresses, China Falls from #2 to #7
Bo Qu
Tao Yan
Rongbo Shao
Zhanglin He
Published: September 5, 2018
Malware
Trend Reports
Vulnerabilities
CVE-2018-8174
ELink
Executive Summary
In Q2, the United States was number one for hosting malicious domains and exploit kits.
Unit 42 regularly analyzes statistical data from our Email Link Analysis (ELINK) to understand the patterns and trends in current web threats. This blog outlines our analysis for April – June (Q2) 2018 and follows up our previous blog analyzing web-based threats for January – March (Q1) 2018 that can be found here . We also provide detailed analysis of attacks against CVE-2018-8174 (a vulnerabil
Unit42
Web-based Threats-2018 Q2: U.S. Remains #1 in Malicious Web Addresses, China Falls from #2 to #7
blogs_unit42·2018-09-05·CVSS 7.5
CVE-2018-8174 [HIGH] Web-based Threats-2018 Q2: U.S. Remains #1 in Malicious Web Addresses, China Falls from #2 to #7
Executive Summary
In Q2, the United States was number one for hosting malicious domains and exploit kits.
Unit 42 regularly analyzes statistical data from our Email Link Analysis (ELINK) to understand the patterns and trends in current web threats. This blog outlines our analysis for April – June (Q2) 2018 and follows up our previous blog analyzing web-based threats for January – March (Q1) 2018 that can be found here. We also provide detailed analysis of attacks against CVE-2018-8174 (a vulnerability we discuss below) using the Double Kill exploit.
What we found this quarter was that vulnerabilities under attack remained consistent, including very old vulnerabilities. One new vulnerability used zero-day attacks did rocket to near the top of the list.
The United States remained the num
Zscaler
Exploit kits go Cryptomining | Zscaler Blog
blogs_zscaler·2018-08-07
Exploit kits go Cryptomining | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Tenable
Underminer Exploit Kit: How Tenable Can Help
blogs_tenable·2018-07-31
Underminer Exploit Kit: How Tenable Can Help
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Underminer Exploit Kit: How Tenable Can Help
blogs_tenable·2018-07-31
Underminer Exploit Kit: How Tenable Can Help
Blog / Cyber Exposure Alerts
Subscribe
# Underminer Exploit Kit: How Tenable Can Help
Tenable Research
July 31, 2018
2 Min Read
The “Underminer” exploit kit is having widespread impact in Asian countries, particularly Japan. Thankfully, mitigation is relatively simple and involves patching and other well-known security best practices.
Contrary to popular belief, the exploit kit is not dead yet. “Underminer,” an exploit kit named and discovered by Trend Micro, is having widespread impact in Asian countries, particularly Japan. Its nefarious bootkit affects the system’s boot sectors and delivers the coin mining payload named Hidden Mellifera.
While the continued decline of Adobe Flash has led to a reduction in the prevalence of Exploit Kits, enterprises need to remember this attack ve
Trendmicro
Bootkit, Miner Delivered by New Underminer Exploit Kit
blogs_trendmicro·2018-07-26
Bootkit, Miner Delivered by New Underminer Exploit Kit
Cyber Threats
# Bootkit, Miner Delivered by New Underminer Exploit Kit
The newly discovered Underminer exploit kit delivers a bootkit that infects the system’s boot sectors as well as a cryptocurrency-mining malware named Hidden Mellifera.
By: Jaromir Horejsi, Joseph C Chen, Chaoying Liu
2018/07/26
Read time: ( words)
Save to Folio
Updated as of July 27, 2018, 2:08 AM, PDT to include a report about Underminer in November 2017.
Updated as of July 26, 2018, 11:02 PM, PDT to include an updated visualization for Figure 1.
We discovered a new exploit kit we named Underminer that employs capabilities used by other exploit kits to deter researchers from tracking its activity or reverse engineering the payloads. Underminer delivers a bootkit that infects the system’s boot sectors as well a
Trendmicro
Down but Not Out: Recent Exploit Kit Activities
blogs_trendmicro·2018-07-02·CVSS 7.5
[HIGH] Down but Not Out: Recent Exploit Kit Activities
Exploits & Vulnerabilities
# Down but Not Out: Recent Exploit Kit Activities
Based on the exploit kits’ latest activities, it appears they and their users are shifting tactics by joining the bandwagon, like capitalizing on cryptocurrency’s popularity or using off-the-rack malware.
By: Martin Co, Joseph C Chen
2018/07/02
Read time: ( words)
Save to Folio
Exploit kits may be down, but they’re not out. While they're still using the same techniques that involve malvertisements or embedding links in spam and malicious or compromised websites, their latest activities are making them significant factors in the threat landscape again. This is the case with Rig and GrandSoft, as well as the private exploit kit Magnitude — exploit kits we found roping in relatively recent vulnerabilities to de
Unit42
The Old and New: Current Trends in Web-based Threats
blogs_unit42·2018-06-20·CVSS 9.3
[CRITICAL] The Old and New: Current Trends in Web-based Threats
Summary
In this blog, Unit 42 is sharing analysis and statistics from our Email Link Analysis (ELINK) from the first quarter of 2018 and highlighting interesting findings of current web threats. We will first describe statistical information about CVEs, malicious URLs and Exploit Kits (EKs), then discuss the current life cycle of these web-based threats, and wrap up with two case studies about evolving EKs and a cryptocurrency miner.
Statistics analysis
CVEs
In the first quarter of 2018, we found 1583 malicious URLs across 496 different domains. Attackers used at least 8 old and public vulnerabilities as shown in Figure 1. The Top 3 CVEs used are
1. CVE-2014-6332: exploited by 774 malicious URLs
2. CVE-2016-0189: exploited by 219 malicious URLs
3. CVE-2015-5122: exploited by 85 malici
Unit42
The Old and New: Current Trends in Web-based Threats
blogs_unit42·2018-06-20·CVSS 9.3
CVE-2014-6332 [CRITICAL] The Old and New: Current Trends in Web-based Threats
Threat Research Center
Trend Reports
Vulnerabilities
## The Old and New: Current Trends in Web-based Threats
Tao Yan
Bo Qu
Zhanglin He
Rongbo Shao
Published: June 20, 2018
Malware
Trend Reports
Vulnerabilities
CVE-2014-6332
CVE-2016-0189
EK
Exploit kit
KaiXin
Rig
Sundown
Summary
In this blog, Unit 42 is sharing analysis and statistics from our Email Link Analysis (ELINK) from the first quarter of 2018 and highlighting interesting findings of current web threats. We will first describe statistical information about CVEs, malicious URLs and Exploit Kits (EKs), then discuss the current life cycle of these web-based threats, and wrap up with two case studies about evolving EKs and a cryptocurrency miner.
Statistics analysis
CVEs
In the first quarter of 2018, we found 1
Trendmicro
Rig Abuses CVE-2018-8174 to Deliver Monero Miner
blogs_trendmicro·2018-05-31·CVSS 8.8
CVE-2018-8174 [HIGH] Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Exploits & Vulnerabilities
# Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Sometime around February to March last year, we saw the Rig exploit kit’s Seamless campaign adding another gate before the actual landing page.
By: Miguel Carlo Ang, Martin Co, Michael Villanueva
2018/05/31
Read time: ( words)
Save to Folio
An exploit kit such as Rig usually starts off with a threat actor compromising a website to inject a malicious script/code that eventually redirects would-be victims to the exploit kit’s landing page. Sometime around February to March last year, however, we saw Rig’s Seamless campaign adding another layer or gate before the actual landing page.
Along with updates in code, we also observed Rig integrating a cryptocurrency-mining malware as its final payload. Based on the
Zscaler
Top Exploit Kit Activity Roundup, Spring 2018| Zscaler Blog
blogs_zscaler·2018-05-11
Top Exploit Kit Activity Roundup, Spring 2018| Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Securelist
The King is dead. Long live the King!
blogs_securelist·2018-05-09·CVSS 7.5
CVE-2018-8174 [HIGH] The King is dead. Long live the King!
Authors
- Vladislav Stolyarov
- Boris Larin
- Anton Ivanov
## Root cause analysis of the latest Internet Explorer zero day – CVE-2018-8174
In late April 2018, a new zero-day vulnerability for Internet Explorer (IE) was found using our sandbox; more than two years since the last in the wild example (CVE-2016-0189). This particular vulnerability and subsequent exploit are interesting for many reasons. The following article will examine the core reasons behind the latest vulnerability, CVE-2018-8174.
### Searching for the zero day
Our story begins on VirusTotal (VT), where someone uploaded an interesting exploit on April 18, 2018. This exploit was detected by several AV vendors including Kaspersky, specifically by our generic heuristic logic for some older Microsoft Word exploits.
After
Securelist
The King is dead. Long live the King!
blogs_securelist·2018-05-09·CVSS 7.5
CVE-2018-8174 [HIGH] The King is dead. Long live the King!
Authors
Vladislav Stolyarov
Boris Larin
Anton Ivanov
## Root cause analysis of the latest Internet Explorer zero day – CVE-2018-8174
In late April 2018, a new zero-day vulnerability for Internet Explorer (IE) was found using our sandbox; more than two years since the last in the wild example (CVE-2016-0189). This particular vulnerability and subsequent exploit are interesting for many reasons. The following article will examine the core reasons behind the latest vulnerability, CVE-2018-8174.
## Searching for the zero day
Our story begins on VirusTotal (VT), where someone uploaded an interesting exploit on April 18, 2018. This exploit was detected by several AV vendors including Kaspersky, specifically by our generic heuristic logic for some older Microsoft Word exploits.
After the
Zscaler
Top Exploit Kit Activity Roundup - Winter 2018 | Zscaler
blogs_zscaler·2018-01-10
Top Exploit Kit Activity Roundup - Winter 2018 | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Zscaler
Terror Exploit Kit via Malvertising campaign | Zscaler Blog
blogs_zscaler·2017-10-24
Terror Exploit Kit via Malvertising campaign | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Trendmicro
Magnitude Exploit Kit Targets South Korea via Magniber
blogs_trendmicro·2017-10-18
Magnitude Exploit Kit Targets South Korea via Magniber
Ransomware
# Magnitude Exploit Kit Targets South Korea via Magniber
A new ransomware is being distributed by the Magnitude exploit kit: Magniber, which we found targeting South Korea via malvertisements on attacker-owned domains/sites. Magnitude now also appears to expressly target South Korean end users.
By: Joseph C Chen
2017/10/18
Read time: ( words)
Save to Folio
With additional analysis by Edmark Dungca and Matthew Camacho We would like to acknowledge the contributions of Kafeine and @malc0de whom we worked with in this research. Updated as of October 18, 2017, 8:05 PM PDT to include our machine learning-based detection and solution. Updated as of October 19, 2017, 8:25 PM PDT to include Trend Micro's XGen™ security solution.
A new ransomware is being distributed by the Magnitu
Trendmicro
A Closer Look at North Korea’s Internet
blogs_trendmicro·2017-10-17
A Closer Look at North Korea’s Internet
# A Closer Look at North Korea’s Internet
We studied internet traffic going in and out of North Korea and found DDoS attacks and recurring watering hole attacks against North Korean websites and spam waves that originate in part from spambots.
By: Vladimir Kropotov, Philippe Lin, Fyodor Yarochkin, Feike Hacquebord
2017/10/17
Read time: ( words)
Save to Folio
North Korea's presence on the internet is commonly perceived as something that only goes one way: hackers go out, nothing gets in. Incidents like the Sony Pictures hack in 2014 and a couple of global bank heists were reported to be the work of North Korean threat actors. Part of publicly available evidence relies on internet communications that were set up from a North Korean IP address. The internet is thought to be tightly contr
Unit42
FreeMilk: A Highly Targeted Spear Phishing Campaign
blogs_unit42·2017-10-05·CVSS 7.8
CVE-2017-0199 [HIGH] FreeMilk: A Highly Targeted Spear Phishing Campaign
## FreeMilk: A Highly Targeted Spear Phishing Campaign
Juan Cortes
Esmid Idrizovic
Published: October 5, 2017
Malware
Threat Research
FreeMilk
Freenki
N1stAgent
PoohMilk
Spear Phishing
In May 2017, Palo Alto Networks Unit 42 identified a limited spear phishing campaign targeting various individuals across the world. The threat actor leveraged the CVE-2017-0199 Microsoft Word Office/WordPad Remote Code Execution Vulnerability with carefully crafted decoy content customized for each target recipient. Our research showed that the spear phishing emails came from multiple compromised email accounts tied to a legitimate domain in North East Asia. We believe that the threat actor hijacked an existing, legitimate in-progress conversation and posed as the legitimate senders to send mali
Unit42
FreeMilk: A Highly Targeted Spear Phishing Campaign
blogs_unit42·2017-10-05·CVSS 7.8
CVE-2017-0199 [HIGH] FreeMilk: A Highly Targeted Spear Phishing Campaign
In May 2017, Palo Alto Networks Unit 42 identified a limited spear phishing campaign targeting various individuals across the world. The threat actor leveraged the CVE-2017-0199 Microsoft Word Office/WordPad Remote Code Execution Vulnerability with carefully crafted decoy content customized for each target recipient. Our research showed that the spear phishing emails came from multiple compromised email accounts tied to a legitimate domain in North East Asia. We believe that the threat actor hijacked an existing, legitimate in-progress conversation and posed as the legitimate senders to send malicious spear phishing emails to the recipients as shown below in Figure 1.
Figure 1 Conversation Hijacking to Deliver Malware
Upon successful exploitation, the malicious document delivered two mal
Zscaler
Top Exploit Kit Activity Roundup - Summer 2017 | Zscaler
blogs_zscaler·2017-09-12
Top Exploit Kit Activity Roundup - Summer 2017 | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Zscaler
Magnitude Exploit Kit leading to Cerber Ransomware | Zscaler
blogs_zscaler·2017-06-26
Magnitude Exploit Kit leading to Cerber Ransomware | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Zscaler
Top Exploit Kit Activity 2017 | Zscaler Research Blog
blogs_zscaler·2017-06-14
Top Exploit Kit Activity 2017 | Zscaler Research Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Securelist
IT threat evolution Q1 2017. Statistics
blogs_securelist·2017-05-22
IT threat evolution Q1 2017. Statistics
Table of Contents
- Q1 figures
- Mobile threats
- Vulnerable apps exploited by cybercriminals
- Online threats (Web-based attacks)
- Local threats
Authors
- Roman Unuchek
- Fedor Sinitsyn
- Denis Parinov
- Vladislav Stolyarov
## Q1 figures
According to KSN data, Kaspersky Lab solutions detected and repelled 479,528,279 malicious attacks from online resources located in 190 countries all over the world.
79,209,775 unique URLs were recognized as malicious by web antivirus components.
Attempted infections by malware that aims to steal money via online access to bank accounts were registered on 288 thousand user computers.
Crypto ransomware attacks were blocked on 240,799 computers of unique users.
Kaspersky Lab’s file antivirus detected a total of 174,989,956 unique malicious and pot
Securelist
IT threat evolution Q1 2017. Statistics
blogs_securelist·2017-05-22
IT threat evolution Q1 2017. Statistics
Table of Contents
Q1 figures
Mobile threats
Q1 events
The rise of Trojan-Ransom.AndroidOS.Egat
Revamped ZTorg
Asacub awakens
Mobile threat statistics
Distribution of mobile malware by type
TOP 20 mobile malware programs
The geography of mobile threats
Mobile banking Trojans
Mobile Ransomware
Vulnerable apps exploited by cybercriminals
Online threats (Web-based attacks)
Online threats in the banking sector
Geography of attacks
The TOP 10 banking malware families
Ransomware Trojans
The number of users attacked by ransomware
The geography of attacks
Top 10 countries attacked by cryptors
Top 10 most widespread cryptor families
Top 10 countries where online resources are seeded with malware
Countries where users faced the greatest risk of online infection
Local threats
Talos
Threat Spotlight: Sundown Matures
blogs_talos·2017-03-31
Threat Spotlight: Sundown Matures
## Threat Spotlight: Sundown Matures
This post authored by Nick Biasini with contributions from Edmund Brumaghin and Alex Chiu
The last time Talos discussed Sundown it was an exploit kit in transition. Several of the large exploit kits had left the landscape and a couple of strong contenders remain. Sundown was one of the kits still active and poised to make a move, but lacked a lot of the sophistication of the other large kits and had lots of easy identifiers throughout its infection chain. Most of these identifiers have been stripped, new exploits added, and Talos was able to uncover an interesting campaign focused around the bulk purchase of expiring domains through auctions commonly held within the domain resellers market.
## Changes Underway Historically Sundown has done several th
Talos
Threat Spotlight: Sundown Matures
blogs_talos·2017-03-31
Threat Spotlight: Sundown Matures
This post authored by Nick Biasini with contributions from Edmund Brumaghin and Alex Chiu
The last time Talos discussed Sundown it was an exploit kit in transition. Several of the large exploit kits had left the landscape and a couple of strong contenders remain. Sundown was one of the kits still active and poised to make a move, but lacked a lot of the sophistication of the other large kits and had lots of easy identifiers throughout its infection chain. Most of these identifiers have been stripped, new exploits added, and Talos was able to uncover an interesting campaign focused around the bulk purchase of expiring domains through auctions commonly held within the domain resellers market.
## Changes UnderwayHistorically Sundown has done several things that made it easy to identify. Thi
Zscaler
CNACOM Open Source Exploitation via Strategic Web Compromise
blogs_zscaler·2016-12-01·CVSS 7.5
[HIGH] CNACOM Open Source Exploitation via Strategic Web Compromise
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Zscaler
A quick look at recent malvertising exploit chains | Zscaler
blogs_zscaler·2016-09-07
A quick look at recent malvertising exploit chains | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Zscaler
Top Exploit Kit Activity Roundup - Summer 2016 | Zscaler
blogs_zscaler·2016-09-02
Top Exploit Kit Activity Roundup - Summer 2016 | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Qualys
Update: Patch Tuesday May 2016 | Qualys
blogs_qualys·2016-05-12·CVSS 7.5
CVE-2016-4117 [HIGH] Update: Patch Tuesday May 2016 | Qualys
Update: Adobe released the patch for Adobe Flash that addresses the current 0-day CVE-2016-4117 in APSB16-15. It also patches another 24 vulnerabilities that are mostly rated critical. Patch as quickly as possible. Chrome and Internet Explorer 11/Edge users will get their patches from Google and Microsoft automatically.
Original: Today is the second Tuesday of the month, when both Microsoft and Adobe publish the security updates to their products – the so-called Patch Tuesday.
But before we get into the details of their updates for the month (17 in all) let’s reiterate the urgency of another vulnerability that might have slipped by you. The popular open source program ImageMagick is currently under active attack on the Internet. Vulnerability CVE-2016-3714 (called ImageTragick in the ass
Qualys
Update: Patch Tuesday May 2016 | Qualys
blogs_qualys·2016-05-12·CVSS 7.5
CVE-2016-4117 [HIGH] Update: Patch Tuesday May 2016 | Qualys
Update : Adobe released the patch for Adobe Flash that addresses the current 0-day CVE-2016-4117 in APSB16-15 . It also patches another 24 vulnerabilities that are mostly rated critical. Patch as quickly as possible. Chrome and Internet Explorer 11/Edge users will get their patches from Google and Microsoft automatically.
Original : Today is the second Tuesday of the month, when both Microsoft and Adobe publish the security updates to their products – the so-called Patch Tuesday.
But before we get into the details of their updates for the month (17 in all) let’s reiterate the urgency of another vulnerability that might have slipped by you. The popular open source program ImageMagick is currently under active attack on the Internet. Vulnerability CVE-2016-3714 (called ImageTragick in the
Talos
Microsoft Patch Tuesday - May 2016
blogs_talos·2016-05-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - May 2016
## Microsoft Patch Tuesday - May 2016
This post is authored by Holger Unterbrink .
Patch Tuesday for May 2016 has arrived where Microsoft releases their monthly set of security bulletins designed to address security vulnerabilities within their products. This month's release contains 16 bulletins addressing 33 vulnerabilities. Eight bulletins are rated critical, addressing vulnerabilities in Edge, Internet Explorer, Office, Graphic Components, VBScript, and Windows Shell. The remaining bulletins are rated important and address vulnerabilities in Internet Explorer, Office, Windows Kernel, IIS, Media Center, Hyper-V, .NET, and several other Windows components.
## Bulletins Rated Critical Vulnerabilities in Microsoft bulletins MS16-051 through MS16-057 and MS16-064 are rated as critical in
Talos
Microsoft Patch Tuesday - May 2016
blogs_talos·2016-05-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - May 2016
This post is authored by Holger Unterbrink.
Patch Tuesday for May 2016 has arrived where Microsoft releases their monthly set of security bulletins designed to address security vulnerabilities within their products. This month's release contains 16 bulletins addressing 33 vulnerabilities. Eight bulletins are rated critical, addressing vulnerabilities in Edge, Internet Explorer, Office, Graphic Components, VBScript, and Windows Shell. The remaining bulletins are rated important and address vulnerabilities in Internet Explorer, Office, Windows Kernel, IIS, Media Center, Hyper-V, .NET, and several other Windows components.
## Bulletins Rated CriticalVulnerabilities in Microsoft bulletins MS16-051 through MS16-057 and MS16-064 are rated as critical in this month's release.
MS16-051and MS16-
Recorded Future
2017 Vulnerability Report: A Shift in Cybercriminal Preferences | Recorded Future
blogs_recorded_future·CVSS 7.8
[HIGH] 2017 Vulnerability Report: A Shift in Cybercriminal Preferences | Recorded Future
## New Kit, Same Player: Top 10 Vulnerabilities Used by Exploit Kits in 2016
## Key Takeaways
Adobe Flash Player provided six of the top 10 vulnerabilities used by exploit kits in 2016. Since our 2015 ranking, Flash Player’s popularity with cyber criminals remains after increased Adobe security issue mitigation efforts.
Vulnerabilities in Microsoft’s Internet Explorer, Windows, and Silverlight rounded out the top 10 vulnerabilities used by exploit kits. None of the vulnerabilities identified in last year’s report carried over to this year’s top 10.
A 2016 Internet Explorer vulnerability (CVE-2016-0189) saw the most linkage to exploit kits, notably Sundown EK which quickly adopted an exploit in July 2016.
Sundown, RIG, and Neutrino exploit kits filled the void created by Angler Exploit
Recorded Future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018 | Recorded Future
blogs_recorded_future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018 | Recorded Future
## Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
Click here to download the complete analysis as a PDF.
This analysis focuses on an exploit kit, phishing attack, or remote access trojan co-occurrence with a vulnerability from January 1, 2018 to December 31, 2018. We analyzed thousands of sources, including code repositories, deep web forum postings, and dark web sites. This is a follow-up to our 2017 report , and the intended audience includes information security practitioners, especially those supporting vulnerability risk assessments.
## Executive Summary
Many vulnerability management practitioners face the daunting task of prioritizing vulnerabilities without adequate insight into which vulnerabilities are actively exploited by cybercriminals. Here, we’ll attempt to she
Recorded Future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
blogs_recorded_future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
# Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
Click here to download the complete analysis as a PDF.
This analysis focuses on an exploit kit, phishing attack, or remote access trojan co-occurrence with a vulnerability from January 1, 2018 to December 31, 2018. We analyzed thousands of sources, including code repositories, deep web forum postings, and dark web sites. This is a follow-up to our 2017 report, and the intended audience includes information security practitioners, especially those supporting vulnerability risk assessments.
### Executive Summary
Many vulnerability management practitioners face the daunting task of prioritizing vulnerabilities without adequate insight into which vulnerabilities are actively exploited by cybercriminals. Here, we’ll attempt to shed
Recorded Future
2017 Vulnerability Report: A Shift in Cybercriminal Preferences
blogs_recorded_future·CVSS 7.8
[HIGH] 2017 Vulnerability Report: A Shift in Cybercriminal Preferences
# New Kit, Same Player: Top 10 Vulnerabilities Used by Exploit Kits in 2016
### Key Takeaways
- Adobe Flash Player provided six of the top 10 vulnerabilities used by exploit kits in 2016. Since our 2015 ranking, Flash Player’s popularity with cyber criminals remains after increased Adobe security issue mitigation efforts.
- Vulnerabilities in Microsoft’s Internet Explorer, Windows, and Silverlight rounded out the top 10 vulnerabilities used by exploit kits. None of the vulnerabilities identified in last year’s report carried over to this year’s top 10.
- A 2016 Internet Explorer vulnerability (CVE-2016-0189) saw the most linkage to exploit kits, notably Sundown EK which quickly adopted an exploit in July 2016.
- Sundown, RIG, and Neutrino exploit kits filled the void created by Angler Ex
http://www.securityfocus.com/bid/90012http://www.securitytracker.com/id/1035820https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-051https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-053https://www.exploit-db.com/exploits/40118/https://www.virusbulletin.com/virusbulletin/2017/01/journey-and-evolution-god-mode-2016-cve-2016-0189/http://www.securityfocus.com/bid/90012http://www.securitytracker.com/id/1035820https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-051https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-053https://www.exploit-db.com/exploits/40118/https://www.virusbulletin.com/virusbulletin/2017/01/journey-and-evolution-god-mode-2016-cve-2016-0189/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0189
2016-05-11
Published
2022-03-28
Added to CISA KEV
Exploited in the wild