Skip to main content

Hacker group may be exploiting unpatched vulnerability in Adobe Flash Player

adobe exploit scarcruft heartbleed bug hacker
Image used with permission by copyright holder
Kaspersky Lab’s latest blog, written by Costin Raiu, points to a security advisory published by Adobe that warns of a critical vulnerability in Adobe Flash Player version 21.0.0.242 and older for ChromeOS, Linux, Macintosh, and Windows-based operating systems. This vulnerability, called CVE-2016-4171, could cause a crash if exploited and allow hackers to take control of the affected system.

According to Adobe, it’s aware of an exploit of CVE-2016-4171 being used in the wild in limited, targeted attacks. However, the company doesn’t seem to be too worried about the problem, as a fix won’t be offered until Adobe dishes out its monthly security update slated to be released as early as June 16 (just days away).

Recommended Videos

In its security advisory, Adobe actually acknowledged Anton Ivanov and Costin Raiu of Kaspersky Lab for reporting the vulnerability in Flash Player and working with the company to address the issue. Raiu indicated in his follow-up blog that the exploit was uncovered by new technologies inserted into Kaspersky Lab products to identify and block zero-day attacks. This new tech caught and blocked an Adobe Flash zero-day exploit earlier this year, followed by another one just this month.

Please enable Javascript to view this content

Raiu said that the security firm believes a new advanced persistent threat (APT) group internally called “ScarCruft” is behind these attacks. This group has several ongoing operations using two exploits in Adobe Flash and one in Internet Explorer. So far, their victims have resided in a number of countries outside North America including China, India, Kuwait and Romania.

According to the security firm, one of the operations currently in motion is dubbed Operation Daybreak. This attack, launched back in March 2016, focuses on high-profile victims using a zero-day Adobe Flash Player exploit that was previously unknown. Another attack is dubbed Operation Erebus, which uses an older exploit and, according to Raiu, “leverages watering holes.” There may have been a third attack too, but that exploit was patched in April.

In addition to Adobe’s Flash Player security advisory published on Tuesday, Adobe also released a number of security bulletins for Adobe DNG SDK, Adobe Brackets, Adobe Creative Cloud Desktop Application, and ColdFusion. For instance, the company released hotfixes for ColdFusion 10, 11, and the 2016 release that resolve an input validation issue that could be used in reflected cross-site scripting (XSS) attacks. The company recommends that customers update these product installations to the latest release.

Adobe issued security updates for Flash Player just a month ago, addressing vulnerabilities that could allow a hacker to gain control of an affected system. One of the affected versions the security updates addressed was Adobe Flash Player for Microsoft Edge and Internet Explorer 11 v21.0.0.241 and earlier, as well as Adobe Flash Player for Google Chrome v21.0.0.216 and earlier.

As for the latest attack on Adobe Flash Player, Raiu said that Kaspersky Lab will release more details when Adobe patches the vulnerability, which he expects to be on June 16 as Adobe indicated in its security advisory.

“Until then, we confirm that Microsoft EMET is effective at mitigating the attacks,” he added in the blog.

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
AMD flagship GPUs to make a comeback with RDNA successor
AMD Radeon RX 7900 XTX hovers over a raging fire.

A recent leak on the Chiphell forums has revealed AMD's ambitious plans for its upcoming CPU and GPU architectures. According to a post by forum member zhangzhonghao, AMD is preparing to utilize TSMC’s cutting-edge N3E process node for its next-generation Radeon GPUs and potentially for some of its future CPUs.

The leak highlights the development of GPUs based on the new UDNA architecture, which will succeed the current RDNA. These GPUs are expected to include a flagship model capable of competing with Nvidia’s top-tier GeForce RTX cards, addressing the lack of a high-end option in AMD’s current RDNA 4 lineup.

Read more
Intel’s Arc B570 puts up an impressive fight against the RTX 4060
Fans on the Intel Arc B570.

Intel just released one of the best graphics cards you can buy -- the Arc B570. As you can read in my Intel Arc B570 review, it delivers solid gaming performance at 1080p, and at a price we haven't seen in years. But it faces some stiff competition from Nvidia in the form of the RTX 4060.

I put the two budget GPUs on the test bench to see how they hold up in a variety of games, and I'll walk you through the results I gathered. Although both cards are excellent options under $300, Intel's new Arc B570 is hard to argue with considering how much less expensive it is than the Nvidia competition.
Specs and pricing

Read more
Samsung’s 27-inch 5K QD-OLED display is the future of gaming
Odyssey OLED G6

Many tech brands are developing next-generation innovations for upcoming products, giving the industry just a taste of what can be expected in the future.

Samsung is one brand leading the charge, as its Samsung Display sector is a primary supplier for display panels throughout the industry. It recently showcased several upcoming technologies, including a 27-inch 5K QD-OLED display. FlatPanelsHD spoke with Samsung Display at CES 2025, where the publication received a private demo of the next generation QD-OLED monitors with a 220 PPI (pixels per inch) pixel density.

Read more