• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Home
  • About
  • Structure
  • Gradebook

ITACS 5211: Introduction to Ethical Hacking

Wade Mackey

New Adobe Flash Zero-Day Exploit Found Hidden Inside MS Office Docs

December 12, 2018 by Brock Donnelly Leave a Comment

https://thehackernews.com/2018/12/flash-player-vulnerability.html

Here is a complicated exploit. It starts with phishing and an email attachment. While the vulnerability resides in flash Word is necessary for the exploit and within a word doc you need a payload, in this example it is an image file. Once the document is opened the payload unpacks, uses Flash’s vulnerability and then can:

monitoring user activities (keyboard or moves the mouse)
collecting system information and sending it to a remote command-and-control (C&C) server,
executing shellcode,
loading PE in memory,
downloading files
execute code, and
performing self-destruction.

Adobe has since patch the vulnerability.

Filed Under: Week 14: Review of all topics

Reader Interactions

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (14)
  • Week 01: Overview (7)
  • Week 02: TCP/IP and Network Architecture (18)
  • Week 03: Reconnaisance (17)
  • Week 04: Vulnerability Scanning (19)
  • Week 05: System and User Enumeration (17)
  • Week 06: Sniffers (17)
  • Week 07: NetCat and HellCat (15)
  • Week 08: Social Engineering, Encoding and Encryption (21)
  • Week 09: Malware (14)
  • Week 10: Web Application Hacking (17)
  • Week 11: SQL Injection (15)
  • Week 12: Web Services (25)
  • Week 13: Evasion Techniques (8)
  • Week 14: Review of all topics (15)

Copyright © 2026 · Magazine Pro Theme on Genesis Framework · WordPress · Log in