Vulnerabilities Discovered in Adobe Shockwave Player for Windows

Vulnerabilities Discovered in Adobe Shockwave Player for Windows

A critical cybersecurity advisory was issued Tuesday, April 9, 2019, regarding multiple vulnerabilities in Adobe Shockwave Player for Windows. The most severe of these could allow for arbitrary code execution.

What It Is:
Multiple vulnerabilities have been discovered in Adobe Shockwave Player, which could allow for arbitrary code execution. Adobe Shockwave Player was a multimedia platform for building browser-based, interactive applications and video games. It has reached its end of life as of April 9th, 2019, and is no longer supported for users without an enterprise license.

Successful exploitation of these vulnerabilities could result in the attacker gaining control of the affected system. Depending on the privileges associated with this application, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. If this application has been configured to have fewer user rights on the system, exploitation of this vulnerability could have less impact than if it was configured with administrative rights.

See the original Adobe Security Bulletin and the End of Life for Adobe Shockwave notification.

Threat Intelligence:
There have been no reports of these vulnerabilities being exploited in the wild to date.

What It Means:
If your business or organization use Adobe Shockwave Player, you will need to contact your support representative to see if patches are available for your network after appropriate testing. You may also remove Adobe Shockwave Player from any systems that do not have a critical business need for it and migrate to a supported, alternative solution to prevent a possible security breach.

Systems Affected Include:

• Adobe Shockwave Player for Windows version 12.3.4.204 and earlier

Risk:
Government:
• Large and medium government entities: High
• Small government entities: Medium
Businesses:
• Large and medium business entities: High
• Small business entities: Medium
Home users: Low

Technical Summary:
Multiple vulnerabilities have been discovered in Adobe Shockwave Player, which could allow for arbitrary code execution. The details of these vulnerabilities are as follows:

• Seven memory corruption vulnerabilities that could allow for Arbitrary Code Execution. (CVE-2019-7098, CVE-2019-7099, CVE-2019-7100, CVE-2019-7101, CVE-2019-7102, CVE-2019-7103, CVE-2019-7104)

What To Do:
We recommend the following actions be taken:

• Adobe customers with enterprise licenses will continue to receive product support. Consult your support representative to identify whether a patch is available to you.
• For all users, it is recommended to identify and migrate to a supported, alternative solution.
• Remove Shockwave player from any systems that do not have a critical business need for it.
• For business-critical applications that cannot be patched due to lack of an enterprise license, enable heightened monitoring such as network and host intrusion detection systems, and exploit mitigation tools such as Windows Defender Exploit Guard.
• Enable read-only protected view for Microsoft Office.
• Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack.
• Remind users not to visit websites or follow links provided by unknown or untrusted sources.
• Inform and educate users regarding the threats posed by hypertext links contained in emails or attachments especially from untrusted sources.
• Apply the Principle of Least Privilege to all systems and services.

Negative Consequences of Lost or Stolen Data:
The loss or theft of proprietary data can have severe impacts, particularly if the compromise becomes public and sensitive information is exposed. Possible impacts include:

• Temporary or permanent loss of sensitive or proprietary information.
• Disruption to regular operations.
• Financial losses incurred to restore systems and files.
• Potential harm to an organization’s reputation.

Should your agency or business need assistance with the detection of vulnerabilities Adobe Shockwave Player or updates to include patches, Dox can help. Please contact Dox if there is anything we can do to assist in securing your agency, business, or organization.

Thank you for your time and stay safe online.