An additional zero-day vulnerability in Adobe Flash Player is being exploited by cybercriminals through a malicious campaign on the video-sharing website Dailymotion.
The vulnerability, which has been assigned the identifier CVE-2015-0313 , affects Flash Player 16.0.0.296 , and the exploit is delivered to computers running all versions of Internet Explorer and Mozilla Firefox , with Windows 8.1 and earlier, Adobe said in a security advisory published on Monday.
Initial analysis conducted by security researchers indicates that the code exploiting the vulnerability is delivered by the Angler exploit kit, a malicious tool that has been used for two other zero-days that prompted Adobe to release out-of-band security updates for Flash.
Trend Micro threat analyst Peter Pi says that research results show that Dailymotion visitors are directed to multiple websites, ending up on a page hosting the exploit (retilio[.]Com / skillt[.]SWF).
Pi has been credited with reporting the vulnerability to Adobe, along with Elia Florio and Dave Weston of Microsoft.
"It is important to note that the infection is automatic, as the ads are designed to load once when a user visits a site. It is likely that this is not limited to the Dailymotion, as the infection was caused by the advertising platform and not by the content of the website itself," Pi said in a blog post.
Trend Micro has been monitoring the attack since January 14th and a week later, on January 27th, it noticed increased activity related to the malicious IP.
This was the day Adobe published the security advisory announcing that Flash Player 16.0.0.296 closed a then-second zero-day (CVE-2015-0311) and became available for all supported platforms.
According to telemetry data from Trend Micro, most of the systems compromised through this attack are from the United States as they observed 3,294 hits related to the exploit. At present, the malicious ads associated with the attack monitored by Trend Micro appear to be inactive.
However, researchers warn that other attacks can exploit the zero-day vulnerability in Flash Player and recommend disabling the browser plug-in until Adobe releases a secure version. Given the critical severity of the issue, an update is expected this week.
However, yesterday security researcher Kafeine reported that the exploit kit used for the attacks is not Angler, but another tool called Hanjuan Exploit Kit.
