Earlier this week, Adobe updated Flash Player, as a bug allowed an attacker to use malicious Flash files to steal Windows credentials.
The security issue has the identifier CVE-2017-3085 and affects Flash Player versions 23.0.0.162 through 26.0.0.137, running on Windows XP, Vista, 7, 8.x, and 10.
The vulnerability was discovered by Dutch security researcher Björn Ruytenberg and is a variant of an older flaw identified as CVE-2016-4271, which Adobe patched in September 2016.
Adobe has addressed this issue with Flash Player version 23.0.0.162, effectively preventing Flash from making any outbound connections to UNC (Universal Naming Convention) URLs, e.g.:
file://///10.0.0.1/some/file.txt
However, a new bug identified by the same researcher (Ruytenberg) is based on a clever trick that can bypass Adobe's new protection measures.
The researcher explains in a technical post on his blog that an attacker could comply with Adobe's ban on UNC addresses and file paths by loading a Flash file that makes a request to a remote server over HTTP or HTTPS.
Ruytenberg says the attack only works when loading malicious Flash files in Office (2010, 2013, and 2016), Firefox, or Internet Explorer. Chrome and Edge browsers are not affected by the attack.
The vulnerability received a severity rating (CVSS) of 4.3 out of 10. However, the flaw is ideal for targeted attacks aimed at specific companies or individuals, such as in financial or state government espionage campaigns.
