Was used to compromise Amnesty Hong Kong website. The vulnerability in Adobe Flash Player was patched on September, 20 in Adobe Reader and Acrobat on October, 5. The vulnerability was disclosed by Mila Parkour.
The exploit:swf/cve-2010-2884.c
Vulnerability details
Advisory: SB2010100502 - Multiple vulnerabilities in Adobe Reader and Acrobat
Vulnerable component: Adobe Flash Player
CVE-ID: CVE-2010-2884
CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:H/RL:O/RC:C
CWE-ID: CWE-119 - Memory corruption
Description:
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary error when processing malicious SWF files. A remote attacker can create a specially crafted .swf document, trick the victim into opening it, cause memory corruption and execute arbitrary code on vulnerable system.
Successful exploitation of the vulnerability results in compromise of vulnerable system.
Known APT campaigns:
Amnesty International Hong Kong site breach
The hackers compromised the website and were delivering Trojan Gh0st RAT.
External links:
http://www.adobe.com/support/security/advisories/apsa10-03.html
http://www.adobe.com/support/security/bulletins/apsb10-22.html
http://www.adobe.com/support/security/bulletins/apsb10-21.html
https://www.nartv.org/2010/11/12/nobel-peace-prize-amnesty-hk-and-malware/
https://blogs.forcepoint.com/security-labs/second-adobe-0-day-vulnerability-just-one-week-cve-2010-2...
https://security.googleblog.com/2010/09/stay-safe-while-browsing.html
http://www.beyondsecurity.com/scan_pentest_network_vulnerabilities_flash_player_unspecified_code_exe...
http://news.softpedia.com/news/Actively-Exploited-Flash-Player-Vulnerability-Patched-in-Chrome-15696...
http://news.softpedia.com/news/Flash-Zero-Day-Actively-Exploited-in-the-Wild-156238.shtml