  ssj4android Redefining Reality
join:2002-04-14 Wyoming, MI
1 edit | Symantec AV reported Flash exploit on visit to Amazon.com
While I was viewing a page on Amazon.com, SAV detected Bloodhound.Exploit.193 (which is an exploit of this Flash buffer vulnerability) in IE's cache, filename tunnel115[1].swf. I had just clear the cache a few minutes before, and the only other site I had visited was MSN.com a few minutes prior (I never use IE so I never bothered changing the default homepage). I just checked and I still had version 115 of Flash for IE, meaning I was still vulnerable. Would SAV have prevented its execution or am I still possibly infected? It "quarantined" the file, is there any way to check if it's malicious? I tried the "Submit to Symantec Security Response" option, after which auto-protect found the same exploit in file SND1 in folder c:\users\[me]\AppData\Local\Temp\0D5C0000\. Is this it quarantining a copy of a file it's producing itself? I'm using Vista. IE had been asking about opening Flash outside of protected mode, I can't remember if I ever allowed it or not (not lately). |