Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: Newest Adobe Flash and Previous 0 Day Exploit - SANS Internet Storm Center SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Newest Adobe Flash and Previous 0 Day Exploit

A researcher has published some information about two new previously unknown vulnerabilities that appear to be exploitable in Adobe Flash version and previous. Adobe has not yet released an advisory. There is no patch or workaround for the vulnerabilities. As far as I know there have not been any IDS/IPS or anti-virus signatures released yet for the exploit. On the good side this one does not yet appear to have been exploited in the wild. The major operating systems that run Flash all appear to be vulnerable. The vulnerability impacts are full compromise as the user running Flash via remote arbitrary code execution, typically delivered from a malicious web page with a crafted SWF file. Little else is known about the specific nature of the vulnerabilities. CVE CVE-2011-4693 and CVE-2011-4694 have been assigned. This will likely be another major one to keep an eye one in the near future. Particularly as Adobe scrambles to get a patch out and everyone else looks for mitigation strategies.


Adrien de Beaupré

Adrien de Beaupre

353 Posts
ISC Handler
Dec 8th 2011
Has any got a Snort Sig to detect this event yet?

Sign Up for Free or Log In to start participating in the conversation!