Security-X
Forum Security-X => News => Discussion démarrée par: chantal11 le avril 13, 2011, 09:54:16
-
Bonjour,
About a month ago, we blogged about an Adobe Flash Player vulnerability (CVE-2011-0609) that was actively exploited in the wild. That exploit was hidden inside a Microsoft Excel document. Over the weekend, a new Adobe Flash Player 0-day (CVE-2011-0611) was reported by Adobe in a recent advisory (APSA11-02).
It all started with spam emails enticing users to open its attachment, typically a Microsoft Word document (or a zip file of a Microsoft Word document), which contained the malicious Flash exploit inside. Most of the files we have captured with our signature are named:
Fukushima .doc
evaluation about Fukushima Nuclear Accident.zip
首場政見會後最新民調略升-蔡英文粉絲團~聲援 .doc
日志分析.doc
Inside the .doc file a malformed Adobe Flash file is embedded. Once a user opens the document, Flash Player will load the malicious file and exploitation will occur.
Lire la suite sur Microsoft Malware Protection Center (http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploitation.aspx)
Le bulletin de sécurité Adobe Adobe - Security Advisories: APSA11-02 - Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat (http://www.adobe.com/support/security/advisories/apsa11-02.html)
@+