Tuesday, April 12, 2011

CVE-2011-0611 Adobe Flash Zero Day embeded in DOC

information about new zero day in adobe flash player :

Filename: Disentangling Industrial Policy and Competition Policy.doc
Size:176,144 bytes

My analysis of  Disentangling Industrial Policy and Competition Policy.doc
File created 04-Apr-2011 9:50 , by user 7 , and company hust

There are no vulnerabilities in MS Office, there is a vulnerability in embeded swf as was described below.

embeded swf file(local name d:\513.swf)
size 10,421 bytes
decoded action  script

this is heap spray, allocate memory with nop slide=0x11111111.
and load second swf file.

second swf
size 1,484 bytes

SWFTools>swfdump.exe -D 1.swf
[HEADER]        File version: 10
[HEADER]        File size: 1484
[HEADER]        Frame rate: 24.000000
[HEADER]        Frame count: 1
[HEADER]        Movie width: 550.00
[HEADER]        Movie height: 400.00
[045]         4 FILEATTRIBUTES
[00c]      1447 DOACTION
GetU8() out of bounds: TagID = 12

flasm16win>flasm.exe -d 1.swf
movie '1.swf' // flash 10, total frames: 1, frame rate: 24 fps, 550x400 px
frame 0
00000000    push FALSE, 326943637, 326943739
0000000F    oldEquals
00000010    not
00000011    branchIfTrue label2 // offset 1100
00000016    branchIfTrue label1 // offset 24
0000001B    constants 'A', 'B', 'C', 'D', 'E', 'F', 'G', 'H', 'I'  Declared constant pool length 21 differs from calculated length 20

Disassembly may be incomplete: wrong action length encountered
          end // of frame 0

crash exist in Adobe Flash Player plugin .
in my test NPSWF32.dll (
crash at location 100cfc03

this possibly related to tweet :

call [0x11111110+0x08]
to be continue ...


  1. Wow! That's complicated! I'm getting a headache just looking at a couple lines of code. Your really good at coding it seems, so keep up the good work! What is Adobe? Thanks!

  2. I am trying this code, but sorry it's didn't work. Can you give me solution for this. Thanks for it.

  3. HI,
    Can you give me solution for this.I loved all of these posts. A lot of these things we have, but I got some really great ideas.

  4. This is my first time to go to here. I found a lot of appealing stuff in your blog.

  5. Thanks VILLY! I tried it and got some error. Please please help me...I really need it. I have to embed adobe flash in my doc very urgently. I will be very grateful to you.

  6. its nice post about the security thanks for providing such useful information actually there should be proper councling about the Security Course it provides a better security tricks along with to brighten someone's career.....

  7. This is very nice and informative post regarding to security. The C Company provides Security Industry Authority (SIA) registered training courses in Security Operations. This 4-day SIA Licence courses has been designed to meet not only the suggested requirements of today's Security Officer, but those of the future and therefore, we believe goes a step further than those of our competitive associates.

  8. This comment has been removed by the author.

  9. Your blogs are totally worth giving time and energy. vivint security

  10. Thanks for sharing this useful info. Keep updating same way for Adobe day CQ5.

    Regards,Siddu Corporate Training

  11. Its something looks like the machine code. I have learnt about that. Its really hard to understand and writing code too.

  12. Security is the one of the best thing which always give you a sense of Ultra security and protection against the internal as well as external factor
    home security service
    home security solution

  13. I got an intrest in your Blog. It gives me effective information on security systems . I am very impressed with your vast knowledge and insight. It is better than anything I've read in the editorial pages of the newspaper.

  14. i like your postings and knowledge for home security.in my opnion home security is a major part of our home that,s why their are n numbers of companies are involving in.
    So that security is based on alarm systems .

  15. Thank you very much!!!!!!!!!! Great help!!!
    Adobe Support

  16. Security contractor installs and helps monitor home security systems and commercial security systems with monitoring starting at just $14.95 Protection Concepts Atlanta security contractor Atlanta Security provider.

    Atlanta Home Security Systems

  17. EPG Security Group provides security services and protection to executives, high-profile individuals, and organizations from businesses to places of worship to the hospitality industry.
    Protection services MN

  18. Replacing batteries in smoke and carbon monoxide detectors is a simple task to provide protection for your family’s security. If you need help with a more sophisticated fire alarm system, give us a call, Lloyd Security can help provide the additional security you want for your home and family.
    Minneapolis 612.874.9295 | St.paul 651.646.0131 | Toll Free 800.330.0911
    Commercial Security Options

  19. Interesting and beautiful blog lovely presentation thanks for sharing your views.....
    Adobe Technical Support visit my site.....

  20. EPG Security Group has a reputation for effective security and executive protection solutions. EPG's vast experience in the public and private sector, including risk institutions, creates the foundation of risk mitigation and executive protection services.
    Executive Protection

  21. Lloyd Security installs, services, and monitors both residential and Commercial security systems in the Twin Cities.
    Minnetonka home security

  22. Our team of security professionals is here to assist you with any security need big or small. We offer security solutions for your home, business, or special event.
    EPG Security Group

  23. I’m definitely coming again to see these articles and blogs.
    adt security

  24. I am really appreciating very much by seeing your interesting posts.
    custom design security camera system

  25. It will be good and easier to understand to the people if it is written in words instead of coidng language.special event security

  26. This is the nice post and this post is really appreciable and informatics .I like this post too much.
    business security systems atlanta

  27. Thanks a lot for sharing us about this update. Hope you will not get tired on making posts as informative as this.
    hardsten keukenblad

  28. Kamera güvenlik sistemleri, kamera bilgi, alarm kurulumu fiyatları

  29. quality Resin Bound Driveways paths and patios, all technical information found at www.theresinbondedslabcompany.co.uk