Wednesday, July 8, 2015

Adobe Flash:
New UNPATCHED Zero-Day Exploit
Kill Flash Plug-in NOW

--

Thanks to the hacking of a professional hacking company, it has been revealed that there is an ACTIVE zero-day exploit of Adobe Flash in-the-wild. It is being exploited right now. Therefore, it is critical to Stop Using Flash until the exploit is patched.

Critical Adobe Flash, Windows zero-days leak from Hacking Team raid
Security teams scramble to patch serious flaws
From what we've seen so far, inside the leaked source code lies an Adobe Flash exploit for which no patch exists: it can be used against Internet Explorer, Firefox, Chrome and Safari, and affects Flash Player 9 to the latest version, 18.0.0.194.
. . . 
Adobe told us in a statement today that it is working on a patch, which it hopes to release by the end of the week. The vulnerability is present in its plugin software for Windows, OS X and Linux. 
Security Advisory for Adobe Flash Player (APSA15-03)
A critical vulnerability (CVE-2015-5119) has been identified in Adobe Flash Player 18.0.0.194 and earlier versions for Windows, Macintosh and Linux. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.   
Adobe is aware of reports that an exploit targeting this vulnerability has been published publicly. Adobe expects to make updates available on July 8, 2015.
Note: As of this posting, CVE-2015-5119 remains unlisted at CVE.Mitre.org. Therefore, I cannot provide a link to its description.

Meanwhile,
SOLUTIONS:

Remove the Adobe Flash plug-in from your Mac NOW.

For those with an administrator password, this is how:

1) Open the root level Internet Plug-Ins folder, found here:

/Library/Internet Plug-Ins/

2) Locate these two files:
  • Flash Player.plugin
  • flashplayer.xpt
3) Select them both and choose to "Move to Trash", either from the Finder File menu or the contextual menu. (Alternatively, you can move them both to a created holding folder, such as 'Internet Plug-Ins (Disabled). 

4) Quit all your web browsers.

5) Reboot your web browsers. 

- - EXCEPT Chrome! Do Not Use Google Chrome! Why? Because Google embedded Adobe Flash into Chrome. It's stuck there, and you can't get rid of it. 

But, if you're desperate to use Chrome, there are two workarounds:
A) Use Chromium (of any flavor) instead. It does NOT include Flash. Everything else about it (except the default surveillance of your web behavior) is the same as Chrome. 
OR 
B) Follow Google's instructions for turning OFF Flash in Chrome:
  1. Type chrome:plugins in the address bar to open the Plug-ins page.
  1. On the Plug-ins page that appears, find the "Flash" listing. To enable Adobe Flash Player, click the Enable link under its name. To disable Adobe Flash Player completely, click the Disable link under its name.
After you've freed yourself from Adobe Flash, either stay that way (highly recommended) or keep an eye out of a new Adobe Flash update. Watch for a version of Flash higher than 18.0.0 194. That's the current bad version. Do not reinstall that thing again.

I'll also be posting another article here when Adobe fixes this latest zero-day exploit.

:-Derek

--

No comments:

Post a Comment