An Adobe Flash 0day is being actively exploited in the wild


Talos said the exploit is being distributed through a Microsoft Excel document that has a malicious Flash object embedded into it. Once the SWF object is triggered, it installs ROKRAT, a remote administration tool Talos has been tracking since January 2017. Until now, the group behind ROKRAT—which Talos calls Group 123—has relied on social engineering or exploits of older, previously known vulnerabilities that targets hadn't yet patched. This is the first time the group has used a zeroday exploit.

One can embed Flash in Excel? Use case of that shows how out of touch MS are, why even that feature. What's the point of something like Powerpoint then (I know I am exaggerating but not that much really  :P )


