HomeSecurityAdobe: New update resolves vulnerabilities in Flash & Application Manager

Adobe: New update resolves vulnerabilities in Flash & Application Manager

Adobe's monthly patch update is short, but it addresses two critical vulnerabilities in Flash, a common participant in the company's security releases

The company published a security advisory describing the two bugs, which affect Adobe Flash Player desktop, version 32.0.0.238 and earlier on Windows, macOS, and Linux, as well as Adobe Flash Player for Google Chrome on Windows, Linux , and Chrome OS.

Adobe

Additionally, Adobe Flash Player for Microsoft Edge and Internet Explorer 11 version 32.0.0.207 and earlier on Windows 10 and 8.1 are affected.

The first vulnerability, CVE-2019-8070, is a critical bug-after-free bug, while the second, CVE-2019-8069, is an execution issue with the same source method in the software.

If exploited, both security flaws could lead to arbitrary code execution.

Adobe has also issued a fix for the installer used with Adobe Application Manager, version 10.0. An insecure library was found to load the vulnerability, CVE-2019-8076, in the Windows version of the installer that could be exploited to allow DLL hijacking.

“This vulnerability only affects the installer used with Adobe Application Manager,” Adobe said. “CVE-2019-8076 does not affect the existing Application Manager, and there is no workaround for customers running older versions.”

Flash

It is recommended that users either enable automatic updates or upgrade their systems through the product's update mechanism.

In August, Adobe is fixing security issues in various software. In total, 75 vulnerabilities were fixed in Acrobat and Reader, along with 34 bugs in Photoshop, four security flaws in Creative Cloud Desktop, a vulnerability in Adobe Experience Manager, and several smaller fixes for Prelude and After Effects.

The vulnerabilities that have been resolved include out-of-bounds read/write flaws, overflow problems, and injection issues.

Additionally, Microsoft released a security update this week. September Patch Tuesday 2019 comes with 80 fixes, 17 of which were for critical vulnerabilities. Among the fixes were patches for two zero-day privilege escalation vulnerabilities, CVE-2019-1214 and CVE-2019-1215.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS