Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le novembre 01, 2016, 11:00:14

Titre: [Trend]CVE-2016-3298: Microsoft Puts the Lid on Another IE Zero-day Used in AdGholas Campaign
Posté par: igor51 le novembre 01, 2016, 11:00:14
CVE-2016-3298: Microsoft Puts the Lid on Another IE Zero-day Used in AdGholas Campaign

Microsoft?s Patch Tuesday for October fixed another previous zero-day vulnerability in Internet Explorer (IE) via MS16-118 and MS16-126: CVE-2016-3298. Before the lid was put on it, the security flaw was employed alongside CVE-2016-3351 by operators of the AdGholas malvertising campaign, analysis and disclosure of which were made with our collaboration with Proofpoint?s @kafeine last July 2016. The campaign was notable for the economies of scale and scope it achieved in its heyday until its operations were stymied. As shared by @kafeine, it was even integrated in Neutrino exploit kit?s malvertising chain as a malicious JavaScript.


Exploiting CVE-2016-3298 enables attackers to check for specific antivirus (AV) software installed in the system in order to avoid AV detection and threat research/analysis. This sounds innocuous, but determining if the system is unsecure eases?and even automates?the undertaking of sneaking malware into it.


Post from: Trendlabs Security Intelligence Blog - by Trend Micro


CVE-2016-3298: Microsoft Puts the Lid on Another IE Zero-day Used in AdGholas Campaign


Source: CVE-2016-3298: Microsoft Puts the Lid on Another IE Zero-day Used in AdGholas Campaign (http://feeds.trendmicro.com/~r/Anti-MalwareBlog/~3/bMon5Nckj1I/)