PDA

View Full Version : [NEWS]0 day Adobe Shockwave Player


GmG
22-10-2010, 11:04
Security Advisory for Adobe Shockwave Player

A Security Advisory (APSA10-04) (http://www.adobe.com/support/security/advisories/apsa10-04.html) has been posted in regards to a new Adobe Shockwave Player issue (CVE-2010-3653). A critical vulnerability exists in Adobe Shockwave Player 11.5.8.612 and earlier versions on the Windows and Macintosh operating systems. This vulnerability (CVE-2010-3653) could cause a crash and potentially allow an attacker to take control of the affected system. While details about the vulnerability have been disclosed publicly, Adobe is not aware of any attacks exploiting this vulnerability against Adobe Shockwave Player to date.

We will continue to provide updates on this issue via the Security Advisory section of the Adobe website as well as the Adobe PSIRT blog.


http://blogs.adobe.com/psirt/2010/10/security-advisory-for-adobe-shockwave-player-apsa10-04.html

http://www.adobe.com/support/security/advisories/apsa10-04.html

http://secunia.com/advisories/41932

GmG
22-10-2010, 11:05
[...]
While details about the vulnerability have been disclosed publicly, Adobe is not aware of any attacks exploiting this vulnerability against Adobe Shockwave Player to date.
[...]


Ho trovato un sito che sfrutta questo exploit

:mad: :rolleyes: :muro:

sampei.nihira
22-10-2010, 15:10
http://www.exploit-db.com/exploits/15296/

lancetta
23-10-2010, 22:26
Ho trovato un sito che sfrutta questo exploit

:mad: :rolleyes: :muro:

Anche io.. lo sfizio di provare (in ambiente virtuale) disattivo l'antivirus e vedo che succede: ma con account user non è riuscito a far nulla :D
Non sò se per la virtualizzazione in sè o se per i bassi privilegi ;)

OT:
Saluti a tutte e due :D