4、Adobe修复Flash可用于监听用户漏洞
标题:Flash Bug Allows Attackers to Spy on Users via Camera, Microphone
作者信息: December 14, 2016 06:11 PM By Catalin Cimpanu
//BEGIN
In yesterday's monthly security patch, Adobe fixed a bug in Flash Player that would have allowed an attacker to hijack permissions granted to other Flash applets and spy on users via their camera or microphone.
The vulnerability, tracked as CVE-2016-7890, was discovered by security researcher Paulos Yibelo.
According to Yibelo, the bug affected all Flash versions and was fixed with the release of Adobe Flash Player 24.0.0.186.
Adobe classified the issue as "a security bypass vulnerability," but Yibelo contacted Bleeping Computer via Twitter to put the bug in perspective.
Adobe近日修补了其Flash Player的一个安全漏洞。该漏洞报告者认为该漏洞非常严重。
漏洞编号为CVE-2016-7890。所有之前的Flash版本均受到影响,直到最新版Adobe Flash Player 24.0.0.186。
如果成功利用该漏洞,黑客可以劫持用户的权限,偷偷使用用户的摄像头、麦克风等设备,这样您看过的视频或者说过的话,统统对黑客而言都不是秘密了。
//END
Because Flash Player sees the access attempts from a domain to which it the user granted access, the app won't show any warnings or extra prompts.
"This could've been a golden issue for surveillance agencies," Yibelo added.
Besides CVE-2016-7890, Adobe also patched a zero-day vulnerability, CVE-2016-7892, used in targeted attacks against users running Internet Explorer (32-bit) on Windows.
Over the summer Yibelo launched the Zerorose project, which lets users see what exploit kits see.
该漏洞比较隐蔽的是,一旦成功利用,系统不会有任何提示,因为这些已经偷偷获得了用户的许可。
可以想象这个漏洞对于情报监听部门该多么重要和诱惑。
漏洞发现者发起了一个称为ZeroRose的计划,通过该计划,用户能直观的看到各色漏洞被利用的场景。当然除了这个CVE-2016-7890,Adobe公司还发布了另外一个CVE-2016-7892的漏洞,这是一个与32位IE浏览器关的零日漏洞。
点评:披露这个0day漏洞应该就称为白帽子吧? |