It's like a greatest hits album of not knowing how to fucking post.
>>1005491
Researchers with Gigamon Applied Threat Research (ATR) and Qihoo 360 uncovered a phishing campaign that exploits CVE-2018-15982, prompting Adobe to today release an out-of-band emergency update to patch up the flaw.
In its current form, the attack bundles exploit code for the Flash zero-day (a use-after-free() bug) with an ActiveX call that is embedded within an Office document. The attacker delivers the document via a spear-phishing email. ATR noted that some of the samples appear to mimic documents from a Russian medical clinic, though others were not specifically targeted towards any one company or group.
When the target opens the poisoned Doc, the ActiveX plug-in calls up Flash Player to run the attack code. From there, CVE-2018-15982 is exploited and the malware looks to download its real payload; a remote control tool that collects system info, and relays it to a command and control system.
In the meantime, Adobe has issued a patch to address both CVE-2018-15982 and CVE-2018-15983, a separate DLL hijacking privilege escalation flaw reported by Souhardya Sardar of Central Model School Barrackpore.
Users and admins are advised to test and install the patches as soon as possible -- or just dump the damn thing already. ®