Support for Windows XP SP3 will officially end April 8, 2014, meaning users have less than a year to choose which operating system to go with next. For many, the motivation to move off XP to a new operating system hasn’t been very compelling – while Windows 7 may be a reasonable option, Vista wasn’t Read more…
Tags: Endpoint Protection, endpoint suites, hips, Java Vulnerability, McAfee Application Control, Whitelisting, Windows 8, Zero-Day
Update on May 2 Adobe has confirmed this vulnerability and has scheduled a patch release for May 14. Looking back this year’s RSA Conference, you might have the feeling that the current threat landscape is primarily a series of advanced attacks. This concept includes well-known advanced persistent threats (APTs) and zero-day vulnerability exploits. To Read more…
Tags: 0 day vulnerability, Adobe Reader, Advanced Persistent Threat, APT, detection, email tracking service, exploit, PDF, tracking usage, Zero-Day
As promised in our previous blog entry for the recent Adobe Reader PDF zero-day attack, we now offer more technical details on this Reader “sandbox-escape” plan. In order to help readers understand what’s going on there, we first need to provide some background. Adobe Reader’s Sandbox Architecture The Adobe Reader sandbox consists of two processes: Read more…
Tags: ASLR, CVE-2013-0633, CVE-2013-0634, DEP, exploit, exploitation, PDF, sandbox, Zero-Day
The winter of 2013 seems to be “zero-day” season. Right after my colleague Haifei Li analyzed the powerful Flash zero day last week, Adobe sent a security alert for another zero-day attack targeting the latest (and earlier) versions of Adobe Reader. Unlike Internet Explorer zero-day exploits that we have seen in the past, this Reader Read more…
Tags: Adobe Reader, broker, JavaScript, PDF, ROP, sandbox, shellcode, XFA, Zero-Day
Last week, a new security issue surfaced for a popular programming language known as Java. This Java security issue is classified as a zero-day threat, and it spreads malicious files to unprotected computers. A zero-day threat is an attack that exploits a previously unknown vulnerability in a computer application (in this case Java), which means that the attack Read more…
Tags: AllAccess, java, malware, SiteAdvisor, Zero-Day
This blog was updated on January 14. See the end of the file. A new Java zero-day vulnerability is spreading malicious files to infect unprotected users. The threat is dangerous: Just browsing a malicious page or clicking a malicious link in spam is enough to cause an infection when combined with a vulnerable Java version. Read more…
Tags: Blackhole Exploit Kit, Cool Exploit Kit, CVE2013-0422, Exploit Analysis, Exploit-CVE2013-0422, Exploit-CVE2013-0422 Analysis, Exploit-Kits, Java Vulnerability, MBeanInstantiator vulnerability, Nuclear Exploit-Kit, Ransomware, Red Exploit-Kit, vulnerability, Zero-Day, Zero-Day Attack
The Cyber Black Market: While it sounds like something out of a cheesy Hollywood movie, it is a real and thriving commercial hub built on the trade of hacking tools. Almost daily, reports surface that new zero-day exploits are being bought and sold in the underground marketplace, with price tags that typically range from $50,000 Read more…
Tags: Cybercrime, Hackers, Zero-Day
On October 12, McAfee Labs learned of proof-of-concept code exploiting a newly patched Flash Player vulnerability. Adobe had patched this vulnerability in its latest security update on October 8. Our research team rapidly responded to this threat with an in-depth analysis of the root cause and the degree of exploitability. This specific vulnerability occurred due Read more…
Tags: 1-day, ActionScript, Adobe, exploitation, Flash Player, vulnerability, Zero-Day
Yesterday, it was reported that an Internet Explorer zero-day threat was actively being exploited in the wild. We did a quick analysis and have some interesting findings. The exploit contains four parts: Exploit.html. First-stage exploiting web page (initialize variables and load the .swf file). Moh2010.swf. Encrypted SWF using DoSWF, it contains shellcode and heap spray Read more…
Tags: 0day vulnerability, Internet Explorer, ROP, Zero-Day
On June 1, McAfee Labs discovered a new Microsoft Internet Explorer zero-day attack that is active in the wild and exploits a use-after-free vulnerability. We have successfully reproduced it with the latest IE8 and Windows 7. We have confirmed it’s a zero day and have been working with the Microsoft security team for their solutions. Read more…
Tags: ASLR, exploit, Internet Explorer, java, msvcr71.dll, ROP, use after free, vulnerability, Zero-Day
Posts tagged under Zero-Day