Check Point Reference: | CPAI-2013-3489 |
Date Published: | 27 Oct 2013 |
Severity: | Critical |
Last Updated: | Saturday 04 January, 2025 |
Source: | |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | JDK and JRE 7 Update 15 and earlier versions JDK and JRE 6 Update 41 and earlier versions JDK and JRE 5.0 Update 40 and earlier versions SDK and JRE 1.4.2_41 and earlier versions JavaFX 2.2.4 and earlier versions Adobe Reader 9.3 and earlier versions Adobe Acrobat 9.3 and earlier versions Adobe Reader 8.2 and earlier versions Adobe Acrobat 8.2 and earlier versions Adobe Flash Player 10.3.181.23 and earlier versions Adobe Flash Player 10.3.185.23 and earlier versions Adobe Flash Player 10.2.156.12 and earlier versions |
Vulnerability Description | Blackhole is a web exploit kit that operates by delivering malicious payload to the victim's computer. |
Vulnerability Details | Remote attackers can infect users with Blackhole by enticing them to visit a malicious web page. Successful infection will allow the attacker to download additional malware to the target. |
This protection will detect and block Blackhole infection attempts at the EXE payload stage.
In order for the protection to be activated, update your product to the latest update. For information on how to update , go to SBP-2006-05, Protection tab and select the version of your choice.
SmartView Tracker will log the following entries:
Attack Name: Web Client Enforcement Violation
Attack Information: BlackHole Toolkit v2 EXE Payload Stage Code Execution