Auteur Sujet: [FireEye]Operation RussianDoll: Adobe & Windows Zero-Day Exploits Likely Leveraged by Russia’s APT28 in Highly-Targeted Attack  (Lu 2765 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
Operation RussianDoll: Adobe & Windows Zero-Day Exploits Likely
Leveraged by Russia’s APT28 in Highly-Targeted Attack


[html]

FireEye Labs recently detected a limited APT campaign exploiting
  zero-day vulnerabilities in Adobe Flash and a brand-new one in
  Microsoft Windows. Using the     href="/content/fireeye-www/en_US/mandiant/threat-intelligence.html"
    target="_self">Dynamic Threat Intelligence Cloud (DTI), FireEye
  researchers detected a pattern of attacks beginning on April
      13th  href="/content/fireeye-www/en_US/mandiant/threat-intelligence.html">,
  2015. Adobe independently patched the vulnerability (CVE-2015-3043) in
      href="https://helpx.adobe.com/security/products/flash-player/apsb15-06.html">APSB15-06.
  Through correlation of technical indicators and command and control
  infrastructure, FireEye assess that APT28 is probably responsible for
  this activity.


 

Microsoft is aware of the outstanding local privilege escalation
  vulnerability in Windows (CVE-2015-1701). While there is not yet a
  patch available for the Windows vulnerability, updating Adobe Flash to
  the latest version will render this in-the-wild exploit innocuous. We
  have only seen CVE-2015-1701 in use in conjunction with the Adobe
  Flash exploit for CVE-2015-3043. The Microsoft Security Team is
  working on a fix for CVE-2015-1701.


 

Exploit Overview


 

The high level flow of the exploit is as follows:


 

1.


Tags: