Researchers at FirEye Security Firm has discovered yet another security vulnerability exploit in Adobe Flash Player. With the recent vulnerabilities revealed by an Independent Researcher Kafeine, Adobe issued 2 back-to-back security fixes in a single week. But What else now ? Another Zero-Day exploit ? And the Answer is Yes, FirEye experts have revealed another Adobe 0Day vulnerability exploit in Adobe Flash, which is a variant of the Adobe 0Day Vulnerability exploit found in Angler Exploit Kit package. This exploit is different in terms of attack vector used in the exploit. Also, it is found that this exploit is packaged in completely different way.
Mitigation Measures
As told by FirEye researchers, the recent fix provided by Adobe, addressing CVE-2015-0311, will prevent this vulnerability and any other samples relying on CVE-2015-0311 from successfully exploiting victim machines.
Technical Description
The exploit is being served through advertising banners on adult websites, including one Alexa top 1000 site. The Flash exploit is loaded by plain Javascript generated from php that appears to be devoid of any environmental checks or obfuscations that are typically indicative of the Angler EK.
YouTube Switched From Adobe Flash to HTML5
YouTube has recently announced in a blog post that they have stopped using Adobe Flash Player for Video streaming and shifted to HTML5 for Video playback. Adobe showed their inability to incorporate HTML5 when it was released 4 years ago, stating that it didn't support the use of ABR (Adaptive Bitrate), which is very useful in saving bandwidth of the users by buffering the videos seamlessly. But between these years, YouTube worked with various browser vendors and the broader community to bridge the gaps, and now the latest versions of Chrome, IE11, Safari 8 and in beta versions of Mozilla Firefox. The benefits of HTML5 extend beyond web browsers, and it's now also used in smart TVs and other streaming devices.