[This blog was primarily written by Xiaoning Li of Intel Labs, with assistance from Peter Szor of McAfee Labs.] In February 2013, the Adobe Product Security Incident Response Team (PSIRT) released security advisory APSA13-02. In that report they listed two vulnerabilities (CVE-2013-0640 and CVE-2013-0641) that were widely exploited. At Intel Labs and McAfee Labs we Read more…
Tags: Adobe, Adobe Reader, APSA13-02, ASLR, CVE-2013-0640, CVE-2013-0641, DEP, PDF, return-oriented programming, ROP, stack pivoting
As promised in our previous blog entry for the recent Adobe Reader PDF zero-day attack, we now offer more technical details on this Reader “sandbox-escape” plan. In order to help readers understand what’s going on there, we first need to provide some background. Adobe Reader’s Sandbox Architecture The Adobe Reader sandbox consists of two processes: Read more…
Tags: ASLR, CVE-2013-0633, CVE-2013-0634, DEP, exploit, exploitation, PDF, sandbox, Zero-Day
On February 7, Adobe issued a security bulletin warning of zero-day attacks that leverage two Flash vulnerabilities. One (CVE-2013-0634) is related to ActionScript regular expression handling. (Some sources refer to this vulnerability as CVE-2013-0633. We are waiting for Adobe to confirm the proper CVE ID.) McAfee Labs rapidly responded to the threat. While digging in Read more…
Tags: ActionScript, ASLR, CVE-2013-0633, CVE-2013-0634, DEP, exploitation, Flash Player, Zero-Day Attack
On June 1, McAfee Labs discovered a new Microsoft Internet Explorer zero-day attack that is active in the wild and exploits a use-after-free vulnerability. We have successfully reproduced it with the latest IE8 and Windows 7. We have confirmed it’s a zero day and have been working with the Microsoft security team for their solutions. Read more…
Tags: ASLR, exploit, Internet Explorer, java, msvcr71.dll, ROP, use after free, vulnerability, Zero-Day
Posts tagged under ASLR