HomeSecurityZero-day exploit in Flash Player via Angler Exploit Kit

Zero-day exploit in Flash Player via Angler Exploit Kit

A new, previously unknown vulnerability in the latest version of Adobe Flash Player is being exploited by cybercriminals using the Angler Exploit Kit (EK) to send malware to users.

Angler Exploit Kit

Adobe Flash Player was updated last week to version 16.0.0.257, patching a total of nine security holes, but it appears that one vulnerability remains active and cybercriminals have created code to take advantage of it.

French security researcher Kafeine noticed that a version of Angler EK had three exploits for Flash Player vulnerabilities built into it . Two of them were for the web-based attack tool, but a third was present in a few instances and appeared to be unpatched by Adobe's latest patches .

Kafeine observed that the zero-day exploit worked on systems running Windows XP with Internet Explorer 6 through 8, Windows 7 with IE 8, and Windows 8 with IE 10, with the latest version (16.0.0.257) of the Player installed.

The researcher says that users who have fully updated Windows 8.1 installed on their systems, as well as those using Google Chrome, are safe against the malicious attack.

At the moment, there aren't many details about the zero-day vulnerability and how it's being exploited, but the researcher says it would be best to disable Flash Player for the next few days until more information is available.

Malwarebytes analyzed how Angler EK exploits the Flash zero-day and identified the malware it spreads as Bedep, “a distribution botnet that can load multiple payloads onto the infected system.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS