cbcvebase.
CVE-2016-7855
published 2016-11-01

CVE-2016-7855: Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute…

PriorityP181high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
25.20%
97.7th percentile
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.

Affected

8 ranges
VendorProductVersion rangeFixed in
adobeflash_player<= 23.0.0.185
adobeflash_player<= 11.2.202.637
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation

Detection & IOCsextracted from sources · hover to see the quote

domainversiontask[.]com
domainpostlkwarn[.]com
hashc42a0d50eac9399914090f1edc2bda9ac1079edff4528078549c824c4d023ff9
hash45a4a376cb7a36f8c7851713c7541cb7e347dafb08980509069a078d3bcb1405
hashc993c1e10299162357196de33e4953ab9ab9e9359fa1aea00d92e97e7d8c5f2c
hash5dd3066a8ee3ab5b380eb7781c85e4253683cd7e3eee1c29013a7a62cd9bef8c
hashfa8b4f64bff799524f6059c3a4ed5d169e9e7ef730f946ac7ad8f173e8294ed8
hash3bb47f37e16d09a7b9ba718d93cfe4d5ebbaecd254486d5192057c77c4a25363
hash4cbb0e3601242732d3ea7c89b4c0fd1074fae4a6d20e5f3afc3bc153b6968d6e
domainapptaskserver[.]com
domainappservicegroup[.]com
domainjoshel[.]com
domainakamaisoftupdate[.]com
domainUniquecorpind[.]com
  • The exploit is delivered via malicious RTF documents containing embedded OLE Word documents, which in turn embed malicious SWF files; hunt for RTF files with embedded OLE objects that contain SWF content.
  • DealersChoice Variant B loads the malicious SWF and payload entirely in memory without writing to disk; use memory-scanning or behavioral detection rather than relying solely on file-based AV.
  • The Sofacy group uses geolocation filtering on C2 servers to only serve exploit payloads to targets in specific regions; sandbox detonation from non-targeted geographies may not trigger payload delivery.
  • Weaponized documents use the OfficeTestSideloading technique to sideload DLLs via a Microsoft Office performance test module; monitor for unusual DLL loads from Office processes or the OfficeTest registry key.
  • Two decoy documents (NASAMS.doc and Programm_Details.doc) share the unique 'Last Saved By' metadata value 'pain'; this metadata artifact can be used to cluster related Sofacy phishing documents.
  • ·The C2 server randomizes k1, k2, k3, k4 token/key values per request, so these cannot be used as static network signatures.
  • ·The C2 server applies geolocation filtering and will not serve payloads to requests originating from non-targeted regions (e.g., USA), limiting sandbox/automated analysis effectiveness.
  • ·The C2 server serves different exploit SWF files based on the victim's reported Flash Player version; the CVE-2016-7855 SWF (c993c1e1…) is only delivered when the Flash version is reported as 23.0.0.185 or similarly vulnerable.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.