Russian hackers exploit Windows and Flash vulnerabilities

Zero day exploits

FireEye has uncovered new zero-day exploits in both Adobe Flash and Microsoft Windows that are likely to have been used by a widespread Russian cyber espionage campaign.

Both exploits were outlined by FireEye over the weekend in a report that accuses the advanced persistent threat group (APT) known as APT28 that operates out of Russia of exploiting the two vulnerabilities.

Attackers can take advantage of the Flash exploit (CVE-2015-3043) when a victim clicks on a link to a malicious website controlled by attackers. Once on a site an HTML.JS launcher page serves the Flash exploit and this then triggers CVE-2015-3043 that executes shellcode and runs an executable payload on a Windows system. That payload then triggers the previously unreported Windows flaw, CVE-2015-1701, which is able to steal system tokens.

That very Windows flaw is a local privilege escalation vulnerability that executes a callback using the flaw to steal data from the System process before executing code using escalated privileges. Attackers can then modify their stolen system tokens to have the exact same privileges as the System process.

Is there a fix?

FireEye first reported on APT28 back in October and it has linked the current campaign to them by explaining that the exploit brings malware variants similar to APT28 backdoors from malware families it has employed in the past.

Microsoft is currently working on a fix for the vulnerability that doesn't affect Windows 8 or later and Adobe Flash users should update to the newest version of the software to prevent any problems arising.

Latest in Security
person at a computer
Many workers are overconfident at spotting phishing attacks
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Latest in News
Star Wars Knights of the Old Republic
Knights of the Old Republic remake developer Saber Interactive states all its projects are 'still in development'
Circular smart ring
Circular's new smart ring is getting blood pressure and blood glucose monitoring before the Apple Watch
iPad mini 2021
Huawei might have beaten Apple to the folding phone finish line by creating a foldable 'iPad mini'
Google Pixel 9 in green Wintergreen color showing AI features on screen
Multiple hands-on Google Pixel 9a videos have emerged, days ahead of the likely launch
A man getting angry with his laptop.
Windows 11 bug deletes Copilot from the OS – is this the first glitch ever some users will be happy to encounter?
Teams on iPhone and Mac
Microsoft Teams has a whole new way for you to talk to (or annoy) your co-workers