CVE-2018-5002
published 2018-07-09CVE-2018-5002: Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code…
PriorityP278high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-06-13
Exploited in the wild
EPSS
25.35%
97.7th percentile
Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 29.0.0.171 | — |
| adobe | flash_player_desktop_runtime | <= 29.0.0.171 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandopenssl enc -nosalt -aes-128-cbc -d -in payload.bin -out decrypted_payload -K E4DF3353FD6D213E7400EEDA8B164FC0 -iv CC6FC77B877584121AEBCBFD4C23B67C↗
bytes↗
0x789C (zlib magic bytes)
- →The Flash downloader sends an HTTP POST request containing the RSA public key modulus (512-bit, hex-encoded) to the attacker's C2 server to retrieve the encrypted AES key and payload — monitor for HTTP POST requests with large hex-encoded numeric blobs from Flash/Office processes. ↗
- →CVE-2018-5002 is triggered by specially crafted bytecode that bypasses Flash's bytecode verification, writing past the end of a buffer via an out-of-range pointer offset — SWF files with hand-crafted bytecode that fails standard verification are a key indicator. ↗
- →Delivery vector is malicious Office documents with embedded Flash content distributed via targeted email — apply detections for Office documents spawning Flash Player processes or making network connections. ↗
- ·The AES key and IV extracted are specific to one observed sample from the PCAP; other CHAINSHOT deployments will use different randomly generated RSA key pairs and thus different AES keys/IVs per victim session. ↗
- ·The RSA key cracking was only feasible because the attacker used a weak 512-bit key; this decryption approach will not apply if the attacker upgrades to a longer key length. ↗
- ·The first 2 bytes of the POST modulus blob are a version selector (e.g., to retrieve 32-bit vs 64-bit payload) and must be stripped before factoring the modulus. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Adobe Flash Player Stack-based Buffer Overflow Vulnerability
cisa·2022-05-23·CVSS 7.8
CVE-2018-5002 [HIGH] CWE-787 Adobe Flash Player Stack-based Buffer Overflow Vulnerability
Vulnerability: Adobe Flash Player Stack-based Buffer Overflow Vulnerability
Affected: Adobe Flash Player
Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-5002
Remediation Due Date: 2022-06-13
Red Hat
flash-plugin: Arbitrary Code Execution vulnerability (APSB18-19)
vendor_redhat·2018-06-07·CVSS 7.8
CVE-2018-5002 [HIGH] flash-plugin: Arbitrary Code Execution vulnerability (APSB18-19)
flash-plugin: Arbitrary Code Execution vulnerability (APSB18-19)
Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
GHSA
GHSA-3rj8-qvqp-3335: Adobe Flash Player versions 29
ghsa_unreviewed·2022-05-13
CVE-2018-5002 [CRITICAL] CWE-121 GHSA-3rj8-qvqp-3335: Adobe Flash Player versions 29
Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
OSV
CVE-2018-5002: Adobe Flash Player versions 29
osv·2018-07-09·CVSS 7.8
CVE-2018-5002 [HIGH] CVE-2018-5002: Adobe Flash Player versions 29
Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
VulnCheck
Adobe Flash Player Stack-based Buffer Overflow Vulnerability
vulncheck·2018·CVSS 7.8
CVE-2018-5002 [HIGH] CWE-787 Adobe Flash Player Stack-based Buffer Overflow Vulnerability
Adobe Flash Player Stack-based Buffer Overflow Vulnerability
Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.
Affected: Adobe Flash Player
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://twitter.com/craiu/status/1038046509793722368; https://unit42.paloaltonetworks.com/unit42-slicing-dicing-cve-2018-5002-payloads-new-chainshot-malware/; https://securelist.com/cve-2018-8453-used-in-targeted-attacks/88151/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Buy
No detection rules found.
No public exploits indexed.
Unit42
Slicing and Dicing CVE-2018-5002 Payloads: New CHAINSHOT Malware
blogs_unit42·2018-09-06·CVSS 7.8
CVE-2018-5002 [HIGH] Slicing and Dicing CVE-2018-5002 Payloads: New CHAINSHOT Malware
## Slicing and Dicing CVE-2018-5002 Payloads: New CHAINSHOT Malware
Dominik Reichel
Esmid Idrizovic
Published: September 6, 2018
Malware
Threat Research
Vulnerabilities
Adobe
CHAINSHOT
CVE-2018-5002
Zero-day
This story begins with one of our blog authors, who, following the discovery of a new Adobe Flash 0-day , found several documents using the same exploit that were used in targeted attacks. We were also able to collect network captures including the encrypted malware payload. Armed with these initial weaponized documents, we uncovered additional attacker network infrastructure, were able to crack the 512-bit RSA keys, and decrypt the exploit and malware payloads. We have dubbed the malware ‘CHAINSHOT’, because it is a targeted attack with several stages and every stage depen
Unit42
Slicing and Dicing CVE-2018-5002 Payloads: New CHAINSHOT Malware
blogs_unit42·2018-09-06·CVSS 7.8
CVE-2018-5002 [HIGH] Slicing and Dicing CVE-2018-5002 Payloads: New CHAINSHOT Malware
This story begins with one of our blog authors, who, following the discovery of a new Adobe Flash 0-day, found several documents using the same exploit that were used in targeted attacks. We were also able to collect network captures including the encrypted malware payload. Armed with these initial weaponized documents, we uncovered additional attacker network infrastructure, were able to crack the 512-bit RSA keys, and decrypt the exploit and malware payloads. We have dubbed the malware ‘CHAINSHOT’, because it is a targeted attack with several stages and every stage depends on the input of the previous one.
This blog describes the process we took to analyze the malware, how we managed to decrypt the payloads, and then how we found parts of a new attack framework. We also found additional
Securelist
IT threat evolution Q2 2018. Statistics
blogs_securelist·2018-08-06
IT threat evolution Q2 2018. Statistics
Table of Contents
- Q2 figures
- Mobile threats
- Attacks on IoT devices
- Online threats in the financial sector
- Vulnerable apps used by cybercriminals
- Attacks via web resources
- Local threats
Authors
- Victor Chebyshev
- Fedor Sinitsyn
- Denis Parinov
- Alexander Liskin
- Oleg Kupreev
## Q2 figures
According to KSN:
- Kaspersky Lab solutions blocked 962,947,023 attacks launched from online resources located in 187 countries across the globe.
- 351,913,075 unique URLs were recognized as malicious by Web Anti-Virus components.
- Attempted infections by malware designed to steal money via online access to bank accounts were logged on the computers of 215,762 users.
- Ransomware attacks were registered on the computers of 158,921 unique users.
- Our File Anti-Virus logged 192,053,
Securelist
IT threat evolution Q2 2018. Statistics
blogs_securelist·2018-08-06
IT threat evolution Q2 2018. Statistics
Table of Contents
Q2 figures
Mobile threats
General statistics
Distribution of detected mobile apps by type
TOP 20 mobile malware
Geography of mobile threats
Mobile banking Trojans
Mobile ransomware Trojans
Attacks on IoT devices
Telnet attacks
TOP 10 countries by shares of IoT devices infected via Telnet
TOP 10 malware downloaded to infected IoT devices in successful Telnet attacks
SSH attacks
TOP 10 countries by shares of IoT devices attacked via SSH
Online threats in the financial sector
Q2 events
New banking Trojan DanaBot
The peculiar BackSwap technique
Carbanak gang leader detained
Ransomware Trojan uses Doppelgänging technique
General statistics on financial threats
Geography of attacks
TOP 10 countries by percentage of attacked users
TOP 10 banking malware f
Krebs
Adobe Patches Zero-Day Flash Flaw
blogs_krebs·2018-06-07·CVSS 7.8
[HIGH] Adobe Patches Zero-Day Flash Flaw
Adobe has released an emergency update to address a critical security hole in its Flash Player browser plugin that is being actively exploited to deploy malicious software. If you’ve got Flash installed — and if you’re using Google Chrome or a recent version of Microsoft Windows you do — it’s time once again to make sure your copy of Flash is either patched, hobbled or removed.
In an advisory published today, Adobe said it is aware of a report that an exploit for the previously unknown Flash flaw — CVE-2018-5002 — exists in the wild, and “is being used in limited, targeted attacks against Windows users. These attacks leverage Microsoft Office documents with embedded malicious Flash Player content distributed via email.”
The vulnerable versions of Flash include v. 29.0.0.171 and earlier.
Tenable
Adobe Flash Player Has (Another) Critical Zero-Day Vulnerability
blogs_tenable·2018-06-07·CVSS 9.8
CVE-2018-5002 [CRITICAL] Adobe Flash Player Has (Another) Critical Zero-Day Vulnerability
Blog / Cyber Exposure Alerts
Subscribe
# Adobe Flash Player Has (Another) Critical Zero-Day Vulnerability
Steve Tilson
June 7, 2018
2 Min Read
The Adobe Flash Player is widely adopted and a choice target for attackers given its history with vulnerabilities and the potential footprint exploits can have. Adobe consistently provides security updates for critical vulnerabilities. However, CVE-2018-5002 is the second zero-day vulnerability in Adobe Flash Player this year (the earlier one being CVE-2018-4877). Today, Adobe released a security patch for this vulnerability, along with other critical updates. This vulnerability was independently discovered by ICEBRG, Qihoo 360 and Tencent and impacts Adobe Flash Player 29.0.0171 and earlier versions. According to Adobe, the vulnerability is a
Tenable
Adobe Flash Player Has (Another) Critical Zero-Day Vulnerability
blogs_tenable·2018-06-07
Adobe Flash Player Has (Another) Critical Zero-Day Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Zscaler
Zscaler protects against 4 new vulnerabilities for Adobe Flash Player. | Zscaler
blogs_zscaler
Zscaler protects against 4 new vulnerabilities for Adobe Flash Player. | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
CVE-2018-5002 flash-plugin: Arbitrary Code Execution vulnerability (APSB18-19)
bugzilla·2018-06-07·CVSS 7.8
CVE-2018-5002 [HIGH] CVE-2018-5002 flash-plugin: Arbitrary Code Execution vulnerability (APSB18-19)
CVE-2018-5002 flash-plugin: Arbitrary Code Execution vulnerability (APSB18-19)
Adobe Security Bulletin APSB18-19 for Adobe Flash Player describes a flaw that can possibly lead to arbitrary code execution when Flash Player is used to play a specially crafted SWF file:
Stack-based buffer overflow -- CVE-2018-5002
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-19.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1827 https://access.redhat.com/errata/RHSA-2018:1827
http://www.securityfocus.com/bid/104412http://www.securitytracker.com/id/1041058https://access.redhat.com/errata/RHSA-2018:1827https://helpx.adobe.com/security/products/flash-player/apsb18-19.htmlhttps://security.gentoo.org/glsa/201806-02http://www.securityfocus.com/bid/104412http://www.securitytracker.com/id/1041058https://access.redhat.com/errata/RHSA-2018:1827https://helpx.adobe.com/security/products/flash-player/apsb18-19.htmlhttps://security.gentoo.org/glsa/201806-02https://github.com/cisagov/vulnrichment/issues/196https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-5002
2018-07-09
Published
2022-05-23
Added to CISA KEV
Exploited in the wild