Showing posts with label CVE-2015-2419 IE. Show all posts
Showing posts with label CVE-2015-2419 IE. Show all posts

Monday, August 10, 2015

Malware don't need coffee. CVE-2014-2419 (Internet Explorer) and Exploits Kits

Fireeye. CVE-2015-2419 Internet Explorer Double-Free in Angler EK

TL; DR
  • CVE-2015-2419 patched in July, 2015
  • CVE-2015-2419 is a double free vulnerability in jscript9’s native JSON APIs
  • Angler added new obfuscation to the exploit. The landing page fetches a stub of keys and data necessary to run the exploit from the server each time it executes. 
  • Browser checks - the stub of information is sent only to vulnerable browsers and is protected with XTEA over modified Diffie-Hellman exchange.
  • Landing page obfuscation - HTML + JS
  • Victim browser will POST JSON to attacker server
  • The shellcode is RC4 encrypted
  • Payload - Cryptowall Ransomware
Web Analytics