CVE-2012-0158 continues to be used in targeted attacks

Posted by   Virus Bulletin on   Oct 31, 2014

30-month old vulnerability still a popular way to infect systems.

If all you have to worry about are zero-day vulnerabilities, you have got things pretty well sorted. Although it is true that sometimes zero-days are being used to deliver malware (such as the recent use of CVE-2014-4114 by the SandWorm group), in many cases even the more targeted attacks get away with using older, long patched vulnerabilities, exploiting the fact that many users and organisations don't patch as quickly as they should — if at all.

CVE-2012-0158 is one such vulnerability. Patched in April 2012, the buffer overflow vulnerability exists in certain ActiveX controls and can be exploited via a malicious Word, Excel or RTF file.

Despite its age, the vulnerability continues to be used by various attack groups that all appear to operate in the Western Australian time zone. Examples of such groups include the 'Shiqiang Gang' (as reported by McAfee), 'PLEAD' (as reported by Trend Micro), 'NetTraveler' (as reported by Kaspersky) and 'APT12' (as reported by FireEye). Today, G Data published a report on 'TooHash', yet another operation that uses CVE-2012-0158 to infect victims.

Given a number of similarities between these attacks, it is possible that some of the groups behind it are indeed related. It is also possible that none of them are directly related, but that some use the same third-party to write the exploits. After all, not just 'ordinary' cybercrime is getting increasingly commoditized.

In either case, security researchers would do best not to assume CVE-2012-0158 a problem that is well behind us. Two papers published by Virus Bulletin last year may help you understand the technical details of the vulnerability.

In May, Fortinet researcher Ruhai Zhang wrote an article on CVE-2012-0158, explaining the tricks used in exploits of the vulnerability to remain undetected by anti-virus software.

In a VB2013 conference paper, Paul Baccas and Vanja Svajcer (then both at Sophos) took a deep look at RTF files containing an exploit for the vulnerability. A PDF of their paper can be downloaded here.

Posted on 31 October 2014 by Martijn Grooten

twitter.png
fb.png
linkedin.png
googleplus.png
reddit.png

 

Latest posts:

VB2018 paper: Uncovering the wholesale industry of social media fraud: from botnet to bulk reseller panels

Today, we publish the VB2018 paper by Masarah Paquet-Clouston (GoSecure) who looked at the supply chain behind social media fraud.

VB2018 paper: Now you see it, now you don't: wipers in the wild

Today, we publish the VB2018 paper from Saher Naumaan (BAE Systems) who looks at malware variants that contain a wiper functionality. We also publish the recording of her presentation.

Emotet trojan starts stealing full emails from infected machines

The infamous Emotet trojan has added the capability to steal full email bodies from infected machines, opening the possibilities for more targeted spam and phishing campaigns.

VB2018 paper: Who wasn’t responsible for Olympic Destroyer?

Cisco Talos researchers Paul Rascagnères and Warren Mercer were among the first to write about the Olympic Destroyer, the malware that targeted the 2018 PyeongChang Winter Olympic Games. Today, we publish the paper they presented at VB2018 about the…

VB2018 paper: From drive-by download to drive-by mining: understanding the new paradigm

Today, we publish the VB2018 paper by Malwarebytes researcher Jérôme Segura, in which he details the shift from exploit kits to drive-by mining. We also publish the video of his VB2018 presentation.

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.