This critical vulnerability is identified as CVE-2018-5002, impacting Adobe Flash Player 29.0.0.171 and older versions. Recently, Adobe has also released version Flash Player 30.0.0.113 to patch this security flaw.
Adobe issues a fix for Zero-Day vulnerability in Flash Player
Zero-day Vulnerability Exploited through Office Files
According to the Chinese online security company Qihoo 360, attackers are leveraging a zero-day vulnerability in Flash Player to target entities in the Middle East. Experts believe the perpetrators behind these attacks are a state-sponsored cyber espionage group.
In a detailed post about the zero-day vulnerability by Qihoo 360, experts stated: 'We suspect the targeted area of the attacker is Doha, Qatar.'
Experts indicate that hackers are using Office files to exploit the Flash zero-day vulnerability. The attacker sends Office files to victims to download malicious SWF files from remote servers and execute them within the Office document.
Malicious files exploit CVE-2018-5002 to execute code on the user's computer, then infect the victim's computer with other malware.
ICEBRG indicates that the vulnerabilities are triggered when users open documents. Detecting these zero-day attacks is very difficult because the attack documents do not contain any malicious code; all malware is downloaded in the second stage.
Zero-day attacks are prepared within a 3-month timeframe
Experts at Qihoo 360 also emphasize: 'Attackers deploy these plans on cloud services and spend at least 3 months preparing for the attack. Detailed content of phishing attacks is also adjusted according to the target.' 'All recent clues indicate that this is a typical APT attack.'
According to Will Dormann of CERT/CC, in addition to patching actual vulnerabilities, Adobe also adds a dialog box asking users if they want to download SWF files within Office documents.
The latest Adobe Flash Player update is now available for users. To download the new Adobe Flash Player, visit this link.
Download Adobe Flash Player and install it here: Get the Flash Player
In addition to patching CVE-2018-5002, the new Adobe Flash update also includes fixes for 3 other security vulnerabilities.
This marks the second zero-day vulnerability patch for Flash Player discovered this year. Back in January, hackers in North Korea deployed the first zero-day Flash vulnerability (CVE-2018-4878), targeting South Korea.
With just a few days left until the start of the 2018 World Cup in Russia, Google has expanded its search functionality, making it easier for internet users to look up team schedules. This is incredibly convenient for users to track the 2018 World Cup schedule.