cbcvebase.
CVE-2017-11292
published 2017-10-22

CVE-2017-11292: Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the…

PriorityP180high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
12.10%
95.7th percentile
Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.

Affected

6 ranges
VendorProductVersion rangeFixed in
adobeflash_player<= 27.0.0.130
adobeflash_player<= 27.0.0.159
adobeflash_player_desktop_runtime<= 27.0.0.159
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_workstation

Detection & IOCsextracted from sources · hover to see the quote

ip89.45.67.107
urlhxxp://89.45.67[.]107/rss/5uzosoff0u.iaf
urlhxxp://89.45.67[.]107/rss/mo.exe
filenamemo.exe
pathC:\ProgramData\ManagerApp\AdapterTroubleshooter.exe
pathC:\ProgramData\ManagerApp\15b937.cab
pathC:\ProgramData\ManagerApp\install.cab
pathC:\ProgramData\ManagerApp\msvcr90.dll
pathC:\ProgramData\ManagerApp\d3d9.dll
processwinlogon
bytes
NOP sled composed of 0x90 and 0x91 opcodes
  • The Flash exploit is delivered as an ActiveX object embedded in a .docx file; hunt for .docx files containing embedded SWF/Flash ActiveX objects.
  • The first-stage shellcode uses an alternating 0x90/0x91 NOP sled to evade AV detection of large NOP blocks in Flash files; signature rules should account for this mixed-opcode pattern.
  • Fortinet IPS signature 'Adobe.Flash.Malformed.Object.Inheritance.Memory.Corruption' covers this CVE-2017-11292 exploit.
  • ·The Flash exploit SWF is packed with a custom packer also seen in other FinSpy exploits; static analysis of the SWF will require unpacking before the exploit code is visible.
  • ·The FinSpy payload uses a custom virtual machine (VM) with 34 instructions and aplib-packed PCODE, making automated analysis and emulation significantly harder.
  • ·Using the Flash killbit may not fully mitigate the risk as Flash objects can be loaded by applications that do not respect the killbit.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.