Threat Level: green Handler on Duty: Manuel Pelaez

SANS ISC InfoSec Handlers Diary Blog


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
ISC StormCast for Friday, December 9th 2011 http://isc.sans.edu/podcastdetail.html?id=2182

Newest Adobe Flash 11.1.102.55 and Previous 0 Day Exploit

Published: 2011-12-08
Last Updated: 2011-12-08 21:52:32 UTC
by Adrien de Beaupre (Version: 1)
1 comment(s)

A researcher has published some information about two new previously unknown vulnerabilities that appear to be exploitable in Adobe Flash version 11.1.102.55 and previous. Adobe has not yet released an advisory. There is no patch or workaround for the vulnerabilities. As far as I know there have not been any IDS/IPS or anti-virus signatures released yet for the exploit. On the good side this one does not yet appear to have been exploited in the wild. The major operating systems that run Flash all appear to be vulnerable. The vulnerability impacts are full compromise as the user running Flash via remote arbitrary code execution, typically delivered from a malicious web page with a crafted SWF file. Little else is known about the specific nature of the vulnerabilities. CVE CVE-2011-4693 and CVE-2011-4694 have been assigned. This will likely be another major one to keep an eye one in the near future. Particularly as Adobe scrambles to get a patch out and everyone else looks for mitigation strategies.

References:

http://www.securitytracker.com/id/1026392
http://secunia.com/advisories/47161
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4693
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4694

Cheers,
Adrien de Beaupré
intru-shun.ca

1 comment(s)
Opera 11.60 web browser released: security and stability enhancements

Microsoft Security Bulletin Advance Notification for December 2011

Published: 2011-12-08
Last Updated: 2011-12-08 21:43:23 UTC
by Adrien de Beaupre (Version: 1)
0 comment(s)

Microsoft have released the advance bulletin notification for the gifts we will be presented with next week. Too early for Christmas! 14 security bulletins; 3 Critical and 11 Important.

http://technet.microsoft.com/en-us/security/bulletin/ms11-dec

Cheers,
Adrien de Beaupré
intru-shun.ca

 

0 comment(s)
Diary Archives