Adobe confirms flash 0-day, issues security bulletin
adobe.com
adobe.com
According to sources, the attacks exploit a vulnerability in fully-patched versions of Flash, and are being leveraged in targeted spear-phishing campaigns launched against select organizations and individuals that work with or for the U.S. government. Sources say the attacks so far have embedded the Flash exploit inside of Microsoft Word files made to look like important government documents.
Here's a virustotal scan of one of the documents: http://www.virustotal.com/file-scan/report.html?id=1e677420d...
The fact that one AV engine detected it as a 0-day was the source of admonishments or congratulations depending on where the observers stood. Until it was discussed that the one detection was probably an unrelated false positive.
~~~
Additional artifacts from the attack including the spearphising tease and the times they were being sent (early morning friday apr 8) - at the height of the budget battle.
http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611...
Of course, I had no idea that flash could even be embedded in Office applications.
Remote exploits that require no abnormal user action are fucking serious.
While the initial attack is uninterested in you, these things spread widely. There is nothing that has been reported that suggests it is limited to this delivery vehicle - I would assume it is not. In my experience, 2nd or 3rd order exploitations will be active before an adobe fix is released.
Perhaps you work for or with the U.S. Government. Information leakage is fun! ;-)