Adobe has released a series of security fixes as part of its regular Patch Tuesday. For May 2018, Adobe patched a total of five vulnerabilities – one for Flash Player, one for the Creative Cloud Desktop app (the app that launches Photoshop, Illustrator, InDesign, and other Creative Cloud apps), and one for Connect (video conferencing software).
The most dangerous was the Flash Player vulnerability, which allows code to be executed on users' computers. The good news is that there is no evidence so far of hackers exploiting the vulnerabilities, but it is always a good idea to keep your software up to date.
Let's take a closer look at the vulnerabilities.
APSB18-16: The company has released security updates for Flash Player for Windows, Macintosh, Linux, and Chrome OS. The updates address critical vulnerabilities in Flash Player that affect version 29.0.0.140 and earlier. Successful exploitation of the vulnerabilities could lead to arbitrary code execution on a user's computer. (CVE-2018-4944).
APSB18-12: The company has released a security update for the Creative Cloud Desktop app for Windows and macOS. This update resolves a critical vulnerability related to incorrect certificate validation (CVE-2018-4991) and two other vulnerabilities that could be exploited for privilege escalation (CVE-2018-4992) (CVE-2018-4873).
APSB18-18: A critical fix for authentication bypass (CVE-2018-4994) in Connect 9.7.5 and earlier. Successful exploitation could lead to disclosure of sensitive information.
Adobe Flash Player Latest Version : 29.0.0.171
| Vulnerability Category | Vulnerability Impact | Severity | CVE Number |
| Type Confusion | Arbitrary Code Execution | Critical | CVE-2018-4944 |
Adobe Creative Cloud Desktops Application Latest Version : 4.5.0.331
| Vulnerability Category | Vulnerability Impact | Severity | CVE Numbers |
| Improper input validation | Privilege Escalation | Important | CVE-2018-4992 |
| >Improper certificate validation | Security bypass | Critical | CVE-2018-4991 |
| Unquoted Search Path | Privilege Escalation | Important | CVE-2018-4873 |
Adobe Connect Latest Version: 9.7.5. (Upcoming version: 9.8.1)
| Vulnerability Category | Vulnerability Impact | Severity | CVE Number |
| Authentication Bypass | Sensitive Information disclosure | Important | CVE-2018-4994 |
