HomeSecurityAdobe patches 87 vulnerabilities! Update immediately

Adobe patches 87 vulnerabilities! Update immediately

Adobe has just released its monthly updates that fix various vulnerabilities in its products as part of Patch Tuesday. Most of the vulnerabilities are in the company's Acrobat Writer and Reader products.

Of course, the updates apply to all Adobe products (such as the well-known Flash Player application) and the vulnerabilities they fix could allow arbitrary code execution.

Overall, the company has fixed 87 vulnerabilities across all of its Acrobat Flash Player and Adobe Media Encoder programs and announced that it is not aware of which of the vulnerabilities are currently being exploited.

Adobe patches 87 vulnerabilities! Update immediately

“Adobe has released security updates for Adobe Acrobat Writer and Reader for Windows and macOS. These updates address critical and important vulnerabilities in the applications. Successful exploitation could lead to arbitrary code execution in the context of the current user.”

The majority of the vulnerabilities (84 fixed in total) concern the implementation of Adobe Acrobat, the Adobe application that allows users to create and manage PDF files. 36 important information disclosure vulnerabilities and 48 unprovoked code execution vulnerabilities were fixed.

These errors include:

six out-of-bounds write flaws (CVE-2019-7829, CVE-2019-7825, CVE-2019-7822, CVE-2019-7818, CVE-2019-7804, CVE-2019-7800);

a type confusion glitch (CVE-2019-7820),
two heap overflow flaws (CVE-2019-7828, CVE-2019-7827),
a buffer error bug (CVE-2019-7824)
a double free vulnerability (CVE-2019-7784)
and a security bypass (CVE-2019-7779).

Below are the versions of Acrobat Writer and Reader. If you are using any of the following products, please update immediately.

Adobe

Adobe Flash Player, meanwhile, has a critical use-after-free vulnerability that could allow arbitrary code execution “in the context of the current user” on affected systems. The flaw was reported anonymously through Trend Micro’s Zero Day Initiative.

The CVE-2019-7837 flaw exists in Adobe Flash Player for Desktop Runtime, Google Chrome, Microsoft Edge, and Internet Explorer 11 (version 32.0.0.171 and earlier). Those using these applications should update to version 32.0.0.192.

Finally, there are two flaws in Adobe Media Encoder version 13.0.2, a product that allows users to easily encode audio and video to various formats.

The product has a critical use-after-free glitch (CVE-2019-7842) that could allow remote code execution, as well as a significant information disclosure vulnerability (CVE-2019-7844).

If you are using the application, it would be a good idea to update Media Encoder to version 13.1. The vulnerability was discovered by Trend Micro.

____________________

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS