Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Hacking Team - Zero Day Any Day current page
Link copied

Hacking Team - Zero Day Any Day

Oct 20, 2017
Author:
James Maude Headshot 2024
James Maude
Field Chief Technology Officer
Blog banner default
Hacking Team - Zero Day Any Day
James Maude Headshot 2024
James Maude
Field Chief Technology Officer

In InfoSec these past few weeks it has been impossible to miss the news that the secretive spyware company known as Hacking Team has been breached and their files posted online. This compromise has resulted in 400GB of confidential data being released online and caused widespread embarrassment for the company and clients alike.

Included in the massive data dump were several 0 day vulnerabilities including a previously unknown exploit for Adobe Flash media player - CVE-2015-5119. This exploit allowed attackers to execute code on a victim's machine just by getting them to browse to an infected website. The Hacking Team boasted in their documentation that this was exploiting "the most beautiful Flash bug for the last 4 years".

The publically disclosed proof of concept exploit in Adobe Flash lets the attacker execute code as the logged on user on the targeted system - in this case launching calc.exe to prove that the system has been compromised. In a malicious attack this could be used to launch malicious commands or download and execute further malware payloads.

Here at Avecto we're happy to show how effectively Defendpoint's proactive security stands up to these advanced attacks and 0 days. We took this publically available exploit code and tested it against Defendpoint with our standard corporate policy without any updates or changes.

So what happened? Defendpoint blocked the attack proactively without any need for signatures, updates or threat intel. The malicious website was automatically isolated in the Sandbox along with the vulnerable version of Flash preventing any access to the user's data.

Zero day any day - executable blocked

When Adobe Flash was exploited not only was it isolated from the users profile but attempts to execute were blocked by Defendpoint's unique context aware Application Control which can distinguish between user interactions and content executing in the Sandbox.

The policy is configured to pop up a simple message to warn users and record an event in the log for security teams to review.

Zero day any day - screenshot

To extend the exercise further and show how our layers of protection work we decided to allow the exploit to fully run and so disabled our advanced application control. This resulted in the exploit launching its chosen payload in our isolated Sandbox environment. This meant that even if allowed to run, the exploit could still not access the user's data or persist on the system.

So there you have it, proactive defences against zero day threats that stands up to real world attacks.

Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • How to Empower Developers Without Sacrificing Security: A Smarter Approach to Admin Rights
    Aug 15, 2025 How to Empower Developers Without Sacrificing Security: A Smarter Approach to Admin Rights
    Blog
    6m
  • What are SMiShing Attacks?  Have You Been a Victim?
    May 31, 2018 What are SMiShing Attacks? Have You Been a Victim?
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.