The vulnerability has been exploited during Sykipot campaigns and Luckycat attacks.
Vulnerability details
Advisory: SB2010102803 - Remote code execution in Adobe Flash Player
Vulnerable component: Adobe Flash Player
CVE-ID: CVE-2010-3654
CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:H/RL:O/RC:C
CWE-ID: CWE-119 - Memory corruption
Description:
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary when processing .swf files in Adobe Flash Player. A remote attacker can create a specially crafted. swf file, trick the victim into opening it, cause memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Note: this vulnerability is being actively exploited via specially crafted .pdf files.
Known APT campaigns:
Luckycat attacks
The campaign has been active since at least June 2011 and linked to 90 attacks against Indian and Japan institution.
Sykipot campaigns
Sykipot attacks trace back to 2006.
The attackers were sending emails with specially crafted links or content containing JS.Sykipot and Backdoor.Sykipot. Trojans to obtain intellectual property (design, financial, manufacturing, or strategic planning information).
According to Symantec, the Sykipot group has Chinese roots.
Public Exploits:
- Adobe Flash Player < 10.1.53.64 - Action Script Type Confusion Exploit (ASLR + DEP Bypass) [Exploit-DB]
- Adobe Flash Player - 'Button' Remote Code Execution (Metasploit) [Exploit-DB]
External links:
http://www.adobe.com/support/security/advisories/apsa10-05.htm
http://www.adobe.com/support/security/bulletins/apsb10-28.html
http://www.adobe.com/support/security/bulletins/apsb10-26.html?sdid=XKMMHJ2P
http://contagiodump.blogspot.com/2010/10/potential-new-adobe-flash-player-zero.html
https://www.google.com.ua/url?sa=t&rct=j&q=&esrc=s&source=web&cd=19&cad=rja&...
https://blogs.technet.microsoft.com/mmpc/2010/11/16/explore-the-cve-2010-3654-matryoshka/
http://www.eweek.com/c/a/Security/Adobe-Flash-Vulnerability-Advisory-Appears-Alongside-Shockwave-Pat...
http://blog.shavlik.com/new-version-of-adobe-flash-available/
https://blogs.forcepoint.com/security-labs/adobe-flash-player-adobe-reader-and-acrobat-0-day-cve-201...
http://www.rationallyparanoid.com/articles/consistently-vulnerable-systems.html
http://www.pctools.com/security-news/adobe-flash-0day-vulnerability/
https://vulners.com/metasploit/MSF:EXPLOIT/WINDOWS/FILEFORMAT/ADOBE_FLASHPLAYER_BUTTON