CVE-2018-15982
published 2019-01-18CVE-2018-15982: Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary…
PriorityP190high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-08-15
Exploited in the wild
EPSS
82.46%
99.6th percentile
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 31.0.0.153 | — |
| adobe | flash_player_installer | <= 31.0.0.108 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Delivery vector is a spear-phishing document (RAR file containing malicious Flash content) disguised as an employee survey; monitor for RAR archives delivered via email that contain SWF or Flash-related content. ↗
- →Post-exploitation payload masquerades as an Nvidia driver application; hunt for unexpected Nvidia-named executables dropped or executed from non-standard paths (e.g., temp directories, user profile folders). ↗
- →CVE-2018-15982 was integrated into the Spelevo Exploit Kit and used to distribute Maze ransomware; monitor for drive-by exploit kit traffic patterns associated with SpelevoEKFlashContainer AutoFocus tag. ↗
- →CVE-2018-15982 was exploited in a targeted spear-phishing attack against Polyclinic No. 2 affiliated with the Presidential Administration of Russia; the attack chain involved a Chrome extension lure in addition to the survey document. ↗
- ·Affected versions are Adobe Flash Player 31.0.0.153 and earlier, and 31.0.0.108 and earlier; the fixed version is 32.0.0.101. Ensure Flash is updated to 32.0.0.101 or later across all browsers (standalone, Chrome, Edge, IE11). ↗
- ·Adobe Flash Player installed with Google Chrome, Microsoft Edge, and Internet Explorer 11 (Windows 10/8.1) will be automatically updated to 32.0.0.101; standalone Desktop Runtime users must manually trigger the update unless 'Allow Adobe to install updates' is enabled. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-26v8-ffh8-7vqg: Flash Player versions 31
ghsa_unreviewed·2022-05-14
CVE-2018-15982 [CRITICAL] CWE-416 GHSA-26v8-ffh8-7vqg: Flash Player versions 31
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
OSV
CVE-2018-15982: Flash Player versions 31
osv·2019-01-18·CVSS 7.8
CVE-2018-15982 [HIGH] CVE-2018-15982: Flash Player versions 31
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
VulnCheck
Adobe Flash Player Use-After-Free Vulnerability
vulncheck·2018·CVSS 7.8
CVE-2018-15982 [HIGH] CWE-416 Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability
Affected: Adobe Flash Player
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Known Ransomware Campaign Use: Known
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://blogs.360.cn/post/PoisonNeedles_CVE-2018-15982_EN; https://www.africacybersecurityconference.com/document/CrowdStrike_GTR_2019.pdf; https://web.archive.org/web/20220227045141/https://risksense.com/wp-content/uploads/2019/09/RiskSense-Spotlight-Report-Ransomware.pdf; https://www.trendmicro.com/en_us/research/19/i/purple-fox-fileless-malware-with-rookit-component-delivered-by-r
CISA
Adobe Flash Player Use-After-Free Vulnerability
cisa·2022-02-15·CVSS 7.8
CVE-2018-15982 [HIGH] CWE-416 Adobe Flash Player Use-After-Free Vulnerability
Vulnerability: Adobe Flash Player Use-After-Free Vulnerability
Affected: Adobe Flash Player
Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-15982
Remediation Due Date: 2022-08-15
Red Hat
flash-plugin: Arbitrary Code Execution vulnerability (APSB18-42)
vendor_redhat·2018-12-05·CVSS 7.8
CVE-2018-15982 [HIGH] CWE-416 flash-plugin: Arbitrary Code Execution vulnerability (APSB18-42)
flash-plugin: Arbitrary Code Execution vulnerability (APSB18-42)
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
Suricata
ET EXPLOIT Possible Inbound Flash Exploit (CVE-2018-15982)
suricata·2019-08-02·CVSS 7.8
CVE-2018-15982 [HIGH] ET EXPLOIT Possible Inbound Flash Exploit (CVE-2018-15982)
ET EXPLOIT Possible Inbound Flash Exploit (CVE-2018-15982)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Inbound Flash Exploit (CVE-2018-15982)"; flow:established,to_client; http.stat_code; content:"200"; http.content_type; content:"application|2f|x-shockwave-flash"; file.data; content:"FWS"; startswith; content:"cmd.exe|20 2f|c"; distance:0; nocase; fast_pattern; reference:url,www.malware-traffic-analysis.net/2019/08/01/index.html; classtype:attempted-user; sid:2027789; rev:4; metadata:attack_target Client_Endpoint, created_at 2019_08_02, cve CVE_2018_15982, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2024_04_13;)
Trendmicro
Leveraging Data Science to Minimize the Blast Radius of Ransomware Attacks
blogs_trendmicro·2023-03-02
Leveraging Data Science to Minimize the Blast Radius of Ransomware Attacks
Ransomware
# Leveraging Data Science to Minimize the Blast Radius of Ransomware Attacks
In this blog entry, we present a case study that illustrates how data-science techniques can be used to gain valuable insights about ransomware groups' targeting patterns as detailed in our research paper, “What Decision-Makers Need to Know About Ransomware Risk.”
By: Vladimir Kropotov, Robert McArdle, Fyodor Yarochkin, Shingo Matsugaya
2023/03/02
Read time: ( words)
Save to Folio
In partnership with: Erin Burns, Eireann Leverett of Waratah Analytics
As ransomware groups continue to build on their arsenal of tactics, techniques, and procedures (TTPs), it's essential for cybersecurity professionals to assess the levels of risk to their organizations using multiple sources of information for a comp
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Sentinelone
Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone
blogs_sentinelone·2020-11-26·CVSS 7.8
[HIGH] Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone
## Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone
## Overview
Egregor ransomware is an offshoot of the Sekhmet malware family that has been active since mid-September 2020. The ransomware operates by compromising organizations, stealing sensitive user data, encrypting said data, and demanding a ransom to exchange encrypted documents. Egregor is ransomware associated with the cyberattacks against GEFCO and Barnes & Noble, Ubisoft, and numerous others.
Multiple intelligence and security companies believe that there are ties between past, now defunct, Maze affiliates and Egregor. There have been reports of ties to Sekhmet , ProLock , and LockBit as well (both of which have also been tied to Maze). With regard to Sekhmet, there are deep similarities in the configuration form
Sentinelone
Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone - SentinelLabs
blogs_sentinelone·2020-11-25·CVSS 7.8
[HIGH] Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone - SentinelLabs
## Overview
Egregor ransomware is an offshoot of the Sekhmet malware family that has been active since mid-September 2020. The ransomware operates by compromising organizations, stealing sensitive user data, encrypting said data, and demanding a ransom to exchange encrypted documents. Egregor is ransomware associated with the cyberattacks against GEFCO and Barnes & Noble, Ubisoft, and numerous others.
Multiple intelligence and security companies believe that there are ties between past, now defunct, Maze affiliates and Egregor. There have been reports of ties to Sekhmet, ProLock, and LockBit as well (both of which have also been tied to Maze). With regard to Sekhmet, there are deep similarities in the configuration format and obfuscation style. SentinelOne-affiliated security researcher
Unit42
Threat Brief: Maze Ransomware
blogs_unit42·2020-05-08·CVSS 7.8
[HIGH] Threat Brief: Maze Ransomware
## Executive Summary
Since the beginning of the calendar year, Palo Alto Networks has detected an uptick in Maze ransomware samples across multiple industries. As a result, we've created this general threat assessment post on the Maze ransomware activities and full visualization of these techniques can be viewed in the Unit 42 Playbook Viewer.
Maze ransomware, a variant of ChaCha ransomware, was first observed in May 2019 and has targeted organizations in North America, South America, Europe, Asia, and Australia. This ransomware is typically distributed via emails containing weaponized Word or Excel attachments. However, it has also been distributed via exploit kits such as the Spelevo Exploit Kit, which has been used with Flash Player vulnerabilities CVE-2018-15982 and CVE-2018-4878. Ma
Unit42
Threat Brief: Maze Ransomware
blogs_unit42·2020-05-08·CVSS 7.8
[HIGH] Threat Brief: Maze Ransomware
Threat Research Center
High Profile Threats
Ransomware
## Threat Brief: Maze Ransomware
Brittany Barbehenn
Doel Santos
Published: May 8, 2020
High Profile Threats
Ransomware
Maze
SpelevoEK
## Executive Summary
Since the beginning of the calendar year, Palo Alto Networks has detected an uptick in Maze ransomware samples across multiple industries. As a result, we've created this general threat assessment post on the Maze ransomware activities and full visualization of these techniques can be viewed in the Unit 42 Playbook Viewer .
Maze ransomware, a variant of ChaCha ransomware, was first observed in May 2019 and has targeted organizations in North America, South America, Europe, Asia, and Australia. This ransomware is typically distributed via emails containing weaponized
Tenable
Critical Vulnerabilities You Need to Find and Fix to Protect the Remote Workforce
blogs_tenable·2020-04-13
Critical Vulnerabilities You Need to Find and Fix to Protect the Remote Workforce
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Trendmicro
Operation Overtrap Targets Japanese Online Banking Users Via Bottle Exploit Kit and Brand-New Cinobi Banking Trojan
blogs_trendmicro·2020-03-11
Operation Overtrap Targets Japanese Online Banking Users Via Bottle Exploit Kit and Brand-New Cinobi Banking Trojan
Malware
# Operation Overtrap Targets Japanese Online Banking Users Via Bottle Exploit Kit and Brand-New Cinobi Banking Trojan
We discovered a new campaign that we dubbed "Operation Overtrap" that mainly targets online users of various Japanese banks.
By: Jaromir Horejsi, Joseph C Chen
2020/03/11
Read time: ( words)
Save to Folio
We recently discovered a new campaign that we dubbed “Operation Overtrap” for the numerous ways it can infect or trap victims with its payload. The campaign mainly targets online users of various Japanese banks by stealing their banking credentials using a three-pronged attack. Based on our telemetry, Operation Overtrap has been active since April 2019 and has been solely targeting online banking users located in Japan. Our analysis found that this campaign u
Trendmicro
Capesand verwendet öffentliche Exploits und Tools
blogs_trendmicro·2019-11-07
Capesand verwendet öffentliche Exploits und Tools
Ausnutzung von Schwachstellen
## Capesand verwendet öffentliche Exploits und Tools
Die Sicherheitsforscher von Trend Micro haben kürzlich ein neues Exploit Kit namens Capesand entdeckt, das auf neuere Sicherheitslücken in Adobe Flash und Microsoft Internet Explorer (IE) zielt.
By: Elliot Cao, Joseph C Chen, William Gamazo Sanchez Nov 07, 2019 Read time: ( words)
Save to Folio
Originalbeitrag von Elliot Cao, Joseph C. Chen, William Gamazo Sanchez
Die Sicherheitsforscher von Trend Micro haben kürzlich ein neues Exploit Kit namens Capesand entdeckt. Das Exploit Kit zielt auf neuere Sicherheitslücken in Adobe Flash und Microsoft Internet Explorer (IE). Die Recherche offenbarte auch den Missbrauch einer Sicherheitslücke für IE von 2015. Die kriminellen Hintermänner entwickeln das Kit stän
Trendmicro
New Capesand Exploit Kit Reuses Public Exploits, Tools
blogs_trendmicro·2019-11-05
New Capesand Exploit Kit Reuses Public Exploits, Tools
Malware
# New Capesand Exploit Kit Reuses Public Exploits, Tools
We found exploit kit Capesand abusing recently disclosed gaps in Adobe Flash and Internet Explorer (IE). Further investigation showed it also exploits a 2015 flaw in IE, appearing to reuse source code from a publicly shared exploit kit code.
By: Elliot Cao, Joseph C Chen, William Gamazo Sanchez
2019/11/05
Read time: ( words)
Save to Folio
Updated as of 7:00 PM Eastern Standard Time to remove one included image.
We discovered a new exploit kit named Capesand in October 2019. Capesand attempts to exploit recent vulnerabilities in Adobe Flash and Microsoft Internet Explorer (IE). Based on our investigation, it also exploits a 2015 vulnerability for IE. It seems the cybercriminals behind the exploit kit are continuously de
Trendmicro
New Capesand Exploit Kit Reuses Public Exploits, Tools
blogs_trendmicro·2019-11-05
New Capesand Exploit Kit Reuses Public Exploits, Tools
Malware
# New Capesand Exploit Kit Reuses Public Exploits, Tools
We found exploit kit Capesand abusing recently disclosed gaps in Adobe Flash and Internet Explorer (IE). Further investigation showed it also exploits a 2015 flaw in IE, appearing to reuse source code from a publicly shared exploit kit code.
By: Elliot Cao, Joseph C Chen, William Gamazo Sanchez
Nov 05, 2019
Read time: ( words)
Save to Folio
Updated as of 7:00 PM Eastern Standard Time to remove one included image.
We discovered a new exploit kit named Capesand in October 2019. Capesand attempts to exploit recent vulnerabilities in Adobe Flash and Microsoft Internet Explorer (IE). Based on our investigation, it also exploits a 2015 vulnerability for IE. It seems the cybercriminals behind the exploit kit are continuously
Trendmicro
‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
blogs_trendmicro·2019-09-09
‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
Cyber Threats
# ‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
This new iteration of Purple Fox that we came across, delivered by Rig, has a few new tricks up its sleeve. It retains its rootkit component by abusing publicly available code. It also abuses PowerShell making it capable of fileless infection.
By: Johnlery Triunfante, Earle Maui Earnshaw, Michael Jhon Ofiaza
Sep 09, 2019
Read time: ( words)
Save to Folio
Exploit kits may no longer be as prolific as it was back when their activities were detected in the millions, but their recurring activities in the first half of 2019 indicate that they won’t be going away any time soon. The Rig exploit kit, for instance, is known for delivering various payloads — such as downloader trojans, ransomware, cryptocurrency-mining malwar
Trendmicro
‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
blogs_trendmicro·2019-09-09
‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
Cyber Threats
# ‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
This new iteration of Purple Fox that we came across, delivered by Rig, has a few new tricks up its sleeve. It retains its rootkit component by abusing publicly available code. It also abuses PowerShell making it capable of fileless infection.
By: Johnlery Triunfante, Earle Maui Earnshaw, Michael Jhon Ofiaza
2019/09/09
Read time: ( words)
Save to Folio
Exploit kits may no longer be as prolific as it was back when their activities were detected in the millions, but their recurring activities in the first half of 2019 indicate that they won’t be going away any time soon. The Rig exploit kit, for instance, is known for delivering various payloads — such as downloader trojans, ransomware, cryptocurrency-mining malware,
Checkpoint
Cobalt Group Returns To Kazakhstan
blogs_checkpoint·2019-07-31
CVE-2018-15982 Cobalt Group Returns To Kazakhstan
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## Cobalt Group Returns To Kazakhstan
Introduction
Cobalt Group is a financially motivated cyber-crime gang that has been active since at least 2016. The group is mainly interested in carryi
Trendmicro
ShadowGate taucht wieder auf
blogs_trendmicro·2019-07-01
ShadowGate taucht wieder auf
Malware
## ShadowGate taucht wieder auf
Nach fast zwei Jahren der teilweise eingeschränkten Aktivität startet die ShadowGate-Kampagne mit dem Platzieren von Kryptowährungs-Minern mithilfe einer aktualisierten Version des Greenflash Sundown Exploit Kits.
By: Trend Micro Jul 01, 2019 Read time: ( words)
Save to Folio
Originalartikel von Joseph C Chen, Fraud Researcher
Nach fast zwei Jahren der teilweise eingeschränkten Aktivität startet die ShadowGate-Kampagne mit dem Platzieren von Kryptowährungs-Minern mithilfe einer aktualisierten Version des Greenflash Sundown Exploit Kits . Die Angriffe richten sich diesmal auf Unternehmen weltweit statt wie früher auf die Region Asien.
ShadowGate (auch WordsJS) wurde 2015 identifiziert und legte mit Exploit Kits Malware über die kompromittierten
Trendmicro
ShadowGate Returns With Greenflash Sundown Exploit Kit
blogs_trendmicro·2019-06-27
ShadowGate Returns With Greenflash Sundown Exploit Kit
# ShadowGate Returns With Greenflash Sundown Exploit Kit
After almost two years of sporadic restricted activity, the ShadowGate campaign has started delivering cryptocurrency miners with a newly upgraded version of the Greenflash Sundown exploit kit.
By: Joseph C Chen, Chaoying Liu, Nakaya Yoshihiro
2019/06/27
Read time: ( words)
Save to Folio
Updated July 1, 4:20PM: Updated to clarify the product of Revive/OpenX that was compromised.
After almost two years of sporadic restricted activity, the ShadowGate campaign has started delivering cryptocurrency miners with a newly upgraded version of the Greenflash Sundown exploit kit. The campaign has been spotted targeting global victims, after operating mainly in Asia.
Background of the Greenflash Sundown exploit kit
The ShadowGate (also c
Talos
Welcome Spelevo: New exploit kit full of old tricks
blogs_talos·2019-06-27
Welcome Spelevo: New exploit kit full of old tricks
## Welcome Spelevo: New exploit kit full of old tricks
## EXECUTIVE SUMMARY
Exploit kits are an ever-present and often forgotten threat on the landscape today. Their popularity seemed to peak several years ago with the success and eventual downfall of some of the best compromise platforms ever created, including the Angler Exploit Kit . These kits generated millions of dollars from their victims and they are still effective. One of their biggest appeals today is the removal of reliance on user assistance. Increasingly, on the crimeware landscape today, user assistance is required, whether it's through blatant social engineering attacks like ongoing sextortion campaigns or through the countless malspam messages traversing the globe daily, users are required to help achieve infection. That
Talos
Welcome Spelevo: New exploit kit full of old tricks
blogs_talos·2019-06-27
Welcome Spelevo: New exploit kit full of old tricks
## EXECUTIVE SUMMARY
Exploit kits are an ever-present and often forgotten threat on the landscape today. Their popularity seemed to peak several years ago with the success and eventual downfall of some of the best compromise platforms ever created, including the Angler Exploit Kit. These kits generated millions of dollars from their victims and they are still effective. One of their biggest appeals today is the removal of reliance on user assistance. Increasingly, on the crimeware landscape today, user assistance is required, whether it's through blatant social engineering attacks like ongoing sextortion campaigns or through the countless malspam messages traversing the globe daily, users are required to help achieve infection. That is where exploit kits stand alone as an effective web-ba
Trendmicro
ShadowGate Returns With Greenflash Sundown Exploit Kit
blogs_trendmicro·2019-06-27
ShadowGate Returns With Greenflash Sundown Exploit Kit
# ShadowGate Returns With Greenflash Sundown Exploit Kit
After almost two years of sporadic restricted activity, the ShadowGate campaign has started delivering cryptocurrency miners with a newly upgraded version of the Greenflash Sundown exploit kit.
By: Joseph C Chen, Chaoying Liu, Nakaya Yoshihiro
Jun 27, 2019
Read time: ( words)
Save to Folio
Updated July 1, 4:20PM: Updated to clarify the product of Revive/OpenX that was compromised.
After almost two years of sporadic restricted activity, the ShadowGate campaign has started delivering cryptocurrency miners with a newly upgraded version of the Greenflash Sundown exploit kit. The campaign has been spotted targeting global victims, after operating mainly in Asia.
Background of the Greenflash Sundown exploit kit
The ShadowGate (also
Zscaler
Exploit Kit Activity Roundup Spring 2019 | Zscaler Blog
blogs_zscaler·2019-05-31
Exploit Kit Activity Roundup Spring 2019 | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Trendmicro
Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
blogs_trendmicro·2018-12-12·CVSS 7.8
CVE-2018-8611 [HIGH] Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
Exploits & Vulnerabilities
## Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
The just-released Patch Tuesday for December includes a fix for the actively exploited Win32k Elevation of Privilege Vulnerability (CVE-2018-8611).
By: Trend Micro Research Dec 12, 2018 Read time: ( words)
Save to Folio
The just-released Patch Tuesday for December includes a fix for the actively exploited Win32k Elevation of Privilege Vulnerability ( CVE-2018-8611 ). The flaw allows an attacker to exploit a bug in the Windows Kernel and run arbitrary code to install programs; view, change, or delete data; or create new accounts with full user rights. It is also pointed out as likely being used with other bugs in targeted attacks.
The patch release fixes another vulnerability that’s worth noting: CVE-20
Trendmicro
Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
blogs_trendmicro·2018-12-12·CVSS 7.8
CVE-2018-8611 [HIGH] Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
Ausnutzung von Schwachstellen
## Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
The just-released Patch Tuesday for December includes a fix for the actively exploited Win32k Elevation of Privilege Vulnerability (CVE-2018-8611).
By: Trend Micro Research Dec 12, 2018 Read time: ( words)
Save to Folio
The just-released Patch Tuesday for December includes a fix for the actively exploited Win32k Elevation of Privilege Vulnerability ( CVE-2018-8611 ). The flaw allows an attacker to exploit a bug in the Windows Kernel and run arbitrary code to install programs; view, change, or delete data; or create new accounts with full user rights. It is also pointed out as likely being used with other bugs in targeted attacks.
The patch release fixes another vulnerability that’s worth noting: CVE
Trendmicro
Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
blogs_trendmicro·2018-12-12·CVSS 7.8
CVE-2018-8611 [HIGH] Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
Exploits & Vulnerabilities
# Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
The just-released Patch Tuesday for December includes a fix for the actively exploited Win32k Elevation of Privilege Vulnerability (CVE-2018-8611).
By: Trend Micro Research
2018/12/12
Read time: ( words)
Save to Folio
The just-released Patch Tuesday for December includes a fix for the actively exploited Win32k Elevation of Privilege Vulnerability (CVE-2018-8611). The flaw allows an attacker to exploit a bug in the Windows Kernel and run arbitrary code to install programs; view, change, or delete data; or create new accounts with full user rights. It is also pointed out as likely being used with other bugs in targeted attacks.
The patch release fixes another vulnerability that’s worth noting: CVE-2018-8
Trendmicro
Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
blogs_trendmicro·2018-12-12·CVSS 7.8
CVE-2018-8611 [HIGH] Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
Exploits y vulnerabilidades
## Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
The just-released Patch Tuesday for December includes a fix for the actively exploited Win32k Elevation of Privilege Vulnerability (CVE-2018-8611).
By: Trend Micro Research Dec 12, 2018 Read time: ( words)
Save to Folio
The just-released Patch Tuesday for December includes a fix for the actively exploited Win32k Elevation of Privilege Vulnerability ( CVE-2018-8611 ). The flaw allows an attacker to exploit a bug in the Windows Kernel and run arbitrary code to install programs; view, change, or delete data; or create new accounts with full user rights. It is also pointed out as likely being used with other bugs in targeted attacks.
The patch release fixes another vulnerability that’s worth noting: CVE-2
Trendmicro
Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
blogs_trendmicro·2018-12-12·CVSS 7.8
CVE-2018-8611 [HIGH] Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
Exploits & Vulnerabilities
## Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
The just-released Patch Tuesday for December includes a fix for the actively exploited Win32k Elevation of Privilege Vulnerability (CVE-2018-8611).
By: Trend Micro Research 2018/12/12 Read time: ( words)
Save to Folio
The just-released Patch Tuesday for December includes a fix for the actively exploited Win32k Elevation of Privilege Vulnerability ( CVE-2018-8611 ). The flaw allows an attacker to exploit a bug in the Windows Kernel and run arbitrary code to install programs; view, change, or delete data; or create new accounts with full user rights. It is also pointed out as likely being used with other bugs in targeted attacks.
The patch release fixes another vulnerability that’s worth noting: CVE-2018
Trendmicro
Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
blogs_trendmicro·2018-12-12·CVSS 7.8
CVE-2018-8611 [HIGH] Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
Exploits & Vulnerabilities
## Patch Tuesday Fixes Win32k, Windows DNS Server Flaws
The just-released Patch Tuesday for December includes a fix for the actively exploited Win32k Elevation of Privilege Vulnerability (CVE-2018-8611).
By: Trend Micro Research Dec 12, 2018 Read time: ( words)
Save to Folio
The just-released Patch Tuesday for December includes a fix for the actively exploited Win32k Elevation of Privilege Vulnerability ( CVE-2018-8611 ). The flaw allows an attacker to exploit a bug in the Windows Kernel and run arbitrary code to install programmes; view, change, or delete data; or create new accounts with full user rights. It is also pointed out as likely being used with other bugs in targeted attacks.
The patch release fixes another vulnerability that’s worth noting: CVE-
Qualys
December 2018 Patch Tuesday – 39 Vulns, Workstation Patches, Adobe Vulns
blogs_qualys·2018-12-11·CVSS 7.8
[HIGH] December 2018 Patch Tuesday – 39 Vulns, Workstation Patches, Adobe Vulns
This month’s Patch Tuesday addresses 39 vulnerabilities, with 9 of them labeled as Critical. Out of the Criticals, most are browser-related, with the rest including Windows, and .net Framework. A Privilege Escalation vulnerability exists in Windows kernel which has been exploited in wild. Adobe also patched 9 Critical and Important vulnerabilities this month for Adobe Acrobat and Reader.
On the basis of volume and severity this Patch Tuesday is light in weight.
## Workstation Patches
Browser and Scripting Engine patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users. Out of the 9 vulnerabilities, 6 can be exploited through br
Qualys
December 2018 Patch Tuesday – 39 Vulns, Workstation Patches, Adobe Vulns | Qualys
blogs_qualys·2018-12-11·CVSS 7.8
[HIGH] December 2018 Patch Tuesday – 39 Vulns, Workstation Patches, Adobe Vulns | Qualys
This month’s Patch Tuesday addresses 39 vulnerabilities, with 9 of them labeled as Critical. Out of the Criticals, most are browser-related, with the rest including Windows, and .net Framework. A Privilege Escalation vulnerability exists in Windows kernel which has been exploited in wild. Adobe also patched 9 Critical and Important vulnerabilities this month for Adobe Acrobat and Reader.
On the basis of volume and severity this Patch Tuesday is light in weight.
### Workstation Patches
Browser and Scripting Engine patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users. Out of the 9 vulnerabilities, 6 can be exploited through b
Tenable
Adobe Flash Vulnerability Can Lead to Code Execution and Asset Takeover (CVE-2018-15982)
blogs_tenable·2018-12-05·CVSS 7.8
[HIGH] Adobe Flash Vulnerability Can Lead to Code Execution and Asset Takeover (CVE-2018-15982)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Adobe Flash Vulnerability Can Lead to Code Execution and Asset Takeover (CVE-2018-15982)
blogs_tenable·2018-12-05·CVSS 7.8
CVE-2018-15982 [HIGH] Adobe Flash Vulnerability Can Lead to Code Execution and Asset Takeover (CVE-2018-15982)
Blog / Cyber Exposure Alerts
Subscribe
# Adobe Flash Vulnerability Can Lead to Code Execution and Asset Takeover (CVE-2018-15982)
Ryan Seguin
December 5, 2018
2 Min Read
Adobe has issued an out-of-band advisory for CVE-2018-15982. Through the use of a maliciously crafted RAR file, an attacker exploiting this vulnerability can take over the machine of users that run it.
## Background
Adobe has released an out-of-band security bulletin. that includes patches for CVE-2018-15982, a critical arbitrary code execution vulnerability in Adobe Flash which has been used to allegedly attack Polyclinic No. 2, which is affiliated with the Presidential Administration of Russia. Users are encouraged to update all applications that incorporate Flash.
## Analysis
The attack requires a user to open
Recorded Future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018 | Recorded Future
blogs_recorded_future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018 | Recorded Future
## Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
Click here to download the complete analysis as a PDF.
This analysis focuses on an exploit kit, phishing attack, or remote access trojan co-occurrence with a vulnerability from January 1, 2018 to December 31, 2018. We analyzed thousands of sources, including code repositories, deep web forum postings, and dark web sites. This is a follow-up to our 2017 report , and the intended audience includes information security practitioners, especially those supporting vulnerability risk assessments.
## Executive Summary
Many vulnerability management practitioners face the daunting task of prioritizing vulnerabilities without adequate insight into which vulnerabilities are actively exploited by cybercriminals. Here, we’ll attempt to she
Recorded Future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
blogs_recorded_future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
# Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
Click here to download the complete analysis as a PDF.
This analysis focuses on an exploit kit, phishing attack, or remote access trojan co-occurrence with a vulnerability from January 1, 2018 to December 31, 2018. We analyzed thousands of sources, including code repositories, deep web forum postings, and dark web sites. This is a follow-up to our 2017 report, and the intended audience includes information security practitioners, especially those supporting vulnerability risk assessments.
### Executive Summary
Many vulnerability management practitioners face the daunting task of prioritizing vulnerabilities without adequate insight into which vulnerabilities are actively exploited by cybercriminals. Here, we’ll attempt to shed
arXiv
Technical Report -- Expected Exploitability: Predicting the Development of Functional Vulnerability Exploits
arxiv_fulltext·2022-02-03
Technical Report -- Expected Exploitability: Predicting the Development of Functional Vulnerability Exploits
Octavian Suciu,
Connor Nelson ,
Zhuoer Lyu ,
Tiffany Bao ,
Tudor Dumitras
University of Maryland, College Park
State University
comment
\@IEEEpubidpullup6.5
Network and Distributed Systems Security (NDSS) Symposium 2020
23-26 February 2020, San Diego, CA, USA
ISBN 1-891562-61-4
https://dx.doi.org/10.14722/ndss.2020.23xxx
www.ndss-symposium.org
[ ]
comment
empty
## Abstract
Assessing the exploitability of software vulnerabilities at the time of disclosure is difficult and error-prone, as features extracted via technical analysis by existing metrics are poor predictors for exploit development.
Moreover, exploitability assessments suffer from a class bias because ``not exploitable'' labels could be inaccurate.
To overcome these challenges, we propose a new metric, called Expecte
Bugzilla
CVE-2018-15982 flash-plugin: Arbitrary Code Execution vulnerability (APSB18-42)
bugzilla·2018-12-05·CVSS 7.8
CVE-2018-15982 [HIGH] CVE-2018-15982 flash-plugin: Arbitrary Code Execution vulnerability (APSB18-42)
CVE-2018-15982 flash-plugin: Arbitrary Code Execution vulnerability (APSB18-42)
Adobe Security Bulletin APSB18-42 for Adobe Flash Player describes a flaw that can possibly lead to arbitrary code execution when Flash Player is used to play a specially crafted SWF file:
Use after free -- CVE-2018-15982
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-42.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:3795 https://access.redhat.com/errata/RHSA-2018:3795
http://www.securityfocus.com/bid/106116https://access.redhat.com/errata/RHSA-2018:3795https://helpx.adobe.com/security/products/flash-player/apsb18-42.htmlhttps://www.exploit-db.com/exploits/46051/http://www.securityfocus.com/bid/106116https://access.redhat.com/errata/RHSA-2018:3795https://helpx.adobe.com/security/products/flash-player/apsb18-42.htmlhttps://www.exploit-db.com/exploits/46051/https://github.com/cisagov/vulnrichment/issues/195https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-15982
2019-01-18
Published
2022-02-15
Added to CISA KEV
Exploited in the wild