Adobe has released its monthly security bulletin for April 2018. The company patched vulnerabilities in five products: Adobe Flash Player, Adobe Experience Manager (CMS), Adobe InDesign, Adobe Digital Editions-book reader , and Adobe PhoneGap Push Plugin.
As is usually the case, Flash Player received the most patches, as it remains the company's and users' most popular product, although Google has reported a decrease in its usage from 80% in 2014 to less than 8% in 2018. This software is still a major means of transmitting malware, trojans, etc. by malicious users. However, the security updates are rather typical since the company announced a while ago that it will stop supporting Flash Player in 2020, seeing HTML5 gaining ground day by day.
In total, the company fixed 14 security vulnerabilities, distributed as follows: 6 vulnerabilities in Flash Player, 3 in Experience Manager, 2 in InDesign, 2 in Digital Editions, and 1 in PhoneGap Push Plugin. Let's take a closer look at which versions are affected and which vulnerabilities are fixed with the new updates:
- APSB18-08 Security update for Flash Player: Applies to version 29.0.0.113 and earlier. Fixes CVE-2018-4932 to 4937 (Remote Code Execution, Information Disclosure)
- APSB18-10 Security update for Experience Manager: Applies to version 6.3 and earlier. Fixes CVE-2018-4929 to 4931 (Sensitive Information Disclosure)
- APSB18-11 Security update for InDesign: Applies to version 13.0 and earlier. Fixes CVE-2018-4927 and 4928 (Local Privilege Escalation, Arbitrary Code Execution)
- APSB18-13 Security for Digital Editions: Applies to version 4.5.7 and earlier. Fixes CVE-2018-4925 and 4926 (Information Disclosure)
- APSB18-15 Security update for PhoneGap Push Plugin: Applies to version 1.8.0 and earlier. Fixes CVE-2018-4943 (JavaScript code execution in the context of the PhoneGap app)
