Although no attacks have been reported using these vulnerabilities, Adobe is fixing a total of 80 bugs for 9 of its products, the most and most important for Adobe Acrobat and Reader and Adobe Flash Player.
- For Flash Player, the update concerns versions 27.0.0.183 and earlier , which will be upgraded to version 27.0.0.187. It is intended for Windows, Mac, Linux and Chrome OS operating systems, as well as the Google Chrome, Microsoft Edge and Internet Explorer browsers. The 5 vulnerabilities that are fixed are CVE-2017-3112, CVE-2017-3113, CVE-2017-11213, CVE-2017-11215, CVE-2017-11225, which were found and announced by the Zero Day Initiative and China Tecncent Zhanlu Lab.
- For Adobe Acrobat and Reader, the patch fixes a total of 56 vulnerabilities, most of which concern remote code execution, security bypass, and crash bugs. It fixes Acrobat and Reader versions DC012.20098 and earlier as well as Acrobat and Reader versions XI 11.0.22 and earlier.
The other programs are:
- Adobe Photoshop CC (2 remote code execution vulnerabilities)
- Adobe Connect (5 vulnerabilities and 1 network security bypass)
- Adobe DNG Converter (1 vulnerability Memory corruption)
- Adobe InDesign (1 remote code execution vulnerability)
- Adobe Digital Editions (6 information leakage vulnerabilities)
- Shockwave Player (1 remote code execution vulnerability)
- Adobe Experience Manager (3 information leakage vulnerabilities)
📧
Subscribe to the SecNews Newsletter
