New Flash exploit used to infect victims with ransomware
A new zero-day vulnerability in Adobe’s Flash player was recently used to spread ransomware known as Cerber, said Proofpoint.
Proofpoint discovered the bug on 2 April, and a colleague at FireEye confirmed it was a previously-unknown vulnerability.
Adobe issued an advisory 5 April (CVE–2016–1019), followed by a patch.
Despite the vulnerability affecting all versions of Flash Player, attackers only targeted older versions of the software.
“We refer to this type of faulty implementation as a ‘degraded’ mode,” said Proofpoint.
Proofpoint said degraded implementations of potential zero-day exploits offer security researchers and vendors an opportunity to identify and mitigate previously unknown vulnerabilities.
More on Adobe Flash security
Using Flash is like leaving your home open and sending invites to criminals