CVE-2017-11292
published 2017-10-22CVE-2017-11292: Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the…
PriorityP180high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
12.10%
95.7th percentile
Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 27.0.0.130 | — |
| adobe | flash_player | <= 27.0.0.159 | — |
| adobe | flash_player_desktop_runtime | <= 27.0.0.159 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
NOP sled composed of 0x90 and 0x91 opcodes
- →The Flash exploit is delivered as an ActiveX object embedded in a .docx file; hunt for .docx files containing embedded SWF/Flash ActiveX objects. ↗
- →The first-stage shellcode uses an alternating 0x90/0x91 NOP sled to evade AV detection of large NOP blocks in Flash files; signature rules should account for this mixed-opcode pattern. ↗
- →Fortinet IPS signature 'Adobe.Flash.Malformed.Object.Inheritance.Memory.Corruption' covers this CVE-2017-11292 exploit. ↗
- ·The Flash exploit SWF is packed with a custom packer also seen in other FinSpy exploits; static analysis of the SWF will require unpacking before the exploit code is visible. ↗
- ·The FinSpy payload uses a custom virtual machine (VM) with 34 instructions and aplib-packed PCODE, making automated analysis and emulation significantly harder. ↗
- ·Using the Flash killbit may not fully mitigate the risk as Flash objects can be loaded by applications that do not respect the killbit. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Adobe Flash Player Type Confusion Vulnerability
cisa·2022-03-03·CVSS 8.8
CVE-2017-11292 [HIGH] CWE-843 Adobe Flash Player Type Confusion Vulnerability
Vulnerability: Adobe Flash Player Type Confusion Vulnerability
Affected: Adobe Flash Player
Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-11292
Remediation Due Date: 2022-03-24
Red Hat
flash-plugin: remote code execution vulnerability (APSB17-32)
vendor_redhat·2017-10-16·CVSS 8.8
CVE-2017-11292 [HIGH] flash-plugin: remote code execution vulnerability (APSB17-32)
flash-plugin: remote code execution vulnerability (APSB17-32)
Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.
GHSA
GHSA-f6x6-gf9m-8cc3: Adobe Flash Player version 27
ghsa_unreviewed·2022-05-13
CVE-2017-11292 [HIGH] CWE-843 GHSA-f6x6-gf9m-8cc3: Adobe Flash Player version 27
Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.
OSV
CVE-2017-11292: Adobe Flash Player version 27
osv·2017-10-22·CVSS 8.8
CVE-2017-11292 [HIGH] CVE-2017-11292: Adobe Flash Player version 27
Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.
VulnCheck
Adobe Flash Player Type Confusion Vulnerability
vulncheck·2017·CVSS 8.8
CVE-2017-11292 [HIGH] CWE-843 Adobe Flash Player Type Confusion Vulnerability
Adobe Flash Player Type Confusion Vulnerability
Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.
Affected: Adobe Flash Player
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://securelist.com/blackoasis-apt-and-new-targeted-attacks-leveraging-zero-day-exploit/82732/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-03-24
No detection rules found.
No public exploits indexed.
Fortinet
Cybercriminals Exploiting Microsoft’s Vulnerable Dynamic Data Exchange Protocol
blogs_fortinet·2017-11-17·CVSS 8.8
[HIGH] Cybercriminals Exploiting Microsoft’s Vulnerable Dynamic Data Exchange Protocol
FORTIGUARD LABS THREAT RESEARCH
Cybercriminals Exploiting Microsoft’s Vulnerable Dynamic Data Exchange Protocol
By FortiGuard SE Team | November 17, 2017
Visa Payment Systems Intelligence recently announced that cybercriminals are threatening the payments ecosystem by leveraging a vulnerable Microsoft Dynamic Data Exchange protocol in phishing campaigns. This phishing attack relies on the Dynamic Data Exchange (DDE) protocol for infection instead of the usual malicious macros or an exploit kit.
This exploit is related to the Microsoft Security Advisory 4053440 issued on November 8, 2017. It provides guidance on securing Microsoft applications when processing Dynamic Data Exchange (DDE) fields. The DDE protocol enables messages to be sent between Microsoft applications and uses shared da
Securelist
BlackOasis APT and new targeted attacks leveraging zero-day exploit
blogs_securelist·2017-10-16·CVSS 9.8
CVE-2017-11292 [CRITICAL] BlackOasis APT and new targeted attacks leveraging zero-day exploit
Table of Contents
- Introduction
- BlackOasis Background
- Attacks Leveraging CVE-2017-11292
- Targeting and Victims
- Conclusions
- Acknowledgements
- References
- Indicators of compromise
Authors
- GReAT
More information about BlackOasis APT is available to customers of Kaspersky Intelligence Reporting Service. Contact: [email protected]
## Introduction
Kaspersky Lab has always worked closely with vendors to protect users. As soon as we find new vulnerabilities we immediately inform the vendor in a responsible manner and provide all the details required for a fix.
On October 10, 2017, Kaspersky Lab’s advanced exploit prevention systems identified a new Adobe Flash zero day exploit used in the wild against our customers. The exploit was delivered through a Microsoft Offic
Securelist
BlackOasis APT and new targeted attacks leveraging zero-day exploit
blogs_securelist·2017-10-16·CVSS 9.8
CVE-2017-11292 [CRITICAL] BlackOasis APT and new targeted attacks leveraging zero-day exploit
Table of Contents
Introduction
BlackOasis Background
Attacks Leveraging CVE-2017-11292
Payload – mo.exe
Targeting and Victims
Conclusions
Acknowledgements
References
Indicators of compromise
Authors
GReAT
More information about BlackOasis APT is available to customers of Kaspersky Intelligence Reporting Service. Contact: [email protected]
## Introduction
Kaspersky Lab has always worked closely with vendors to protect users. As soon as we find new vulnerabilities we immediately inform the vendor in a responsible manner and provide all the details required for a fix.
On October 10, 2017, Kaspersky Lab’s advanced exploit prevention systems identified a new Adobe Flash zero day exploit used in the wild against our customers. The exploit was delivered through a Microsoft
Bugzilla
CVE-2017-11292 flash-plugin: remote code execution vulnerability (APSB17-32)
bugzilla·2017-10-16·CVSS 8.8
CVE-2017-11292 [HIGH] CVE-2017-11292 flash-plugin: remote code execution vulnerability (APSB17-32)
CVE-2017-11292 flash-plugin: remote code execution vulnerability (APSB17-32)
Adobe Security Bulletin APSB17-32 for Adobe Flash Player describes a type confusion flaw that can possibly lead to remote code execution when Flash Player is used to play a specially crafted SWF file.
External References:
https://helpx.adobe.com/security/products/flash-player/apsb17-32.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:2899 https://access.redhat.com/errata/RHSA-2017:2899
arXiv
Analysis and Correlation of Visual Evidence in Campaigns of Malicious Office Documents
arxiv_fulltext·2021-03-30
Analysis and Correlation of Visual Evidence in Campaigns of Malicious Office Documents
Analysis and Correlation of Visual Evidence in Campaigns of Malicious Office Documents
[1,2]Fran Casino
[3]Nikolaos Totosis
[1]Theodoros Apostolopoulos
[1]Department of Informatics, University Piraeus, 80 Karaoli & Dimitriou str, 18534 Piraeus, Greece
[1]Nikolaos Lykousas
[1,2]Constantinos Patsakis
[2]Information Management Systems Institute of Athena Research Center, Greece
[3]Hatching, Netherlands
## Abstract
Many malware campaigns use Microsoft (MS) Office documents as droppers to download and execute their malicious payload. Such campaigns often use these documents because MS Office is installed in billions of devices and that these files allow the execution of arbitrary VBA code. Recent versions of MS Office prevent the automatic execution of VBA macros, so malware authors try to co
http://www.securityfocus.com/bid/101286http://www.securitytracker.com/id/1039582https://access.redhat.com/errata/RHSA-2017:2899https://helpx.adobe.com/security/products/flash-player/apsb17-32.htmlhttps://security.gentoo.org/glsa/201710-22http://www.securityfocus.com/bid/101286http://www.securitytracker.com/id/1039582https://access.redhat.com/errata/RHSA-2017:2899https://helpx.adobe.com/security/products/flash-player/apsb17-32.htmlhttps://security.gentoo.org/glsa/201710-22https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-11292
2017-10-22
Published
2022-03-03
Added to CISA KEV
Exploited in the wild