Alert level

Exploit:SWF/CVE-2011-0609

(?)

Encyclopedia entry
Updated: Apr 17, 2011  |  Published: Mar 16, 2011

Aliases
  • CVE-2011-0609 (other)
  • APSA11-01 (other)

Alert Level (?)
Severe

Antimalware protection details
Microsoft recommends that you download the latest definitions to get protected.
Detection initially created:
Definition: 1.99.1311.0
Released: Mar 16, 2011


 

Summary

Exploit:SWF/CVE-2011-0609 is a detection for specially crafted Adobe Shockwave flash (.SWF) files that attempt to exploit vulnerabilities in Adobe Flash discussed in CVE-2011-0609 and Adobe Security Advisory APSA11-01.


 

Symptoms

Alert notifications or detections of this malware from installed antivirus or security software may be the only other symptoms.


 

Technical Information (Analysis)

Exploit:SWF/CVE-2011-0609 is a detection for specially crafted Adobe Shockwave flash (.SWF) files that attempt to exploit vulnerabilities in Adobe Flash discussed in CVE-2011-0609 and Adobe Security Advisory APSA11-01.
 
In the wild, this exploit has been observed to be decrypted and loaded at runtime by flash files detected as Exploit:Win32/Shellcode.G or Exploit:Win32/Shellcode.H. The embedded shellcode, once executed, will drop and execute an executable as its main payload. At the time of this writing, the payload drops and executes malware detected as Backdoor:Win32/Poison.M.
 
Additional Information
Exploit:Win32/Shellcode.G and Exploit:Win32/Shellcode.H were found embedded within Microsoft Excel and Word data files and distributed as an attachment detected as Trojan:Win32/Malfws.A or Trojan:Win32/Malfws.B.
 
Analysis by Marian Radu


 

Prevention



 

Recovery

To detect and remove this threat and other malicious software that may be installed in your computer, run a full-system scan with an up-to-date antivirus product such as the following:
 
 
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.

Provide feedback