Adobe has released updates security to address vulnerabilities affecting many of its Windows and macOS products . These vulnerabilities could allow attackers to execute code on devices running vulnerable versions of the software .

The vulnerabilities that Adobe is patching are located in: Adobe Creative Cloud Desktop Application, Adobe InDesign, Adobe Media Encoder, Adobe Premiere Pro, Adobe Photoshop, Adobe After Effects, Adobe Animate, Adobe Dreamweaver, Adobe Illustrator and Marketo.
In total, the company patched 20 vulnerabilities. 18 of them have been rated “critical” and two “serious.”
Adobe urges all users of vulnerable products to update systems to protect themselves from potential attacks.
APSB20-68 Security Update for Adobe Creative Cloud Desktop Application
Adobe has released an update for Adobe InDesign that fixes a vulnerability in the Creative Cloud Desktop Application installer for Windows. The vulnerability could lead to malicious code execution.
Windows users need to install Creative Cloud DesktopApplication 5.3 (old installer) or 2.2 (new installer) to fix this critical error.
| Vulnerability Category | Vulnerability Impact | Severity | CVE Numbers |
| Uncontrolled Search Path | Arbitrary Code Execution | Critical | CVE-2020-24422 |
APSB20-66 Security Update for Adobe InDesign
Adobe also fixed a critical memory error in Adobe InDesign, which could also lead to code execution on Windows systems.
Users are urged to install Adobe InDesign version 16.0 as soon as possible.
| Vulnerability Category | Vulnerability Impact | Severity | CVE Number |
|---|---|---|---|
| Memory Corruption | Arbitrary Code Execution | Critical | CVE-2020-24421 |
APSB20-65 Security updates for Adobe Media Encoder
The new security update also fixes a vulnerability in Adobe Media Encoder, which causes the same problems as the first vulnerability (in the Creative Cloud Desktop Application).
Windows users need to install Adobe Media Encoder version 14.5 .
| Vulnerability Category | Vulnerability Impact | Severity | CVE Numbers |
| Uncontrolled Search Path | Arbitrary Code Execution | Critical | CVE-2020-24423 |
APSB20-64 Security updates for Adobe Premiere Pro
Another vulnerability that allows code execution was found in Adobe Premiere Pro 14.4 and earlier versions.
Windows and macOS users should get the Adobe Premiere Pro 14.5 update.
| Vulnerability Category | Vulnerability Impact | Severity | CVE Numbers |
| Uncontrolled search path element | Arbitrary Code Execution | Critical | CVE-2020-24424 |
APSB20-63 Security Updates for Adobe Photoshop
The company also fixed a similar vulnerability in Adobe Photoshop.
Windows and macOS users should get the Photoshop 21.2.3 update or Photoshop 2021 22.0 to fix this critical vulnerability.
| Vulnerability Category | Vulnerability Impact | Severity | CVE Number |
|---|---|---|---|
| Uncontrolled search path element | Arbitrary code execution | Critical | CVE-2020-24420 |
APSB20-62 Security updates for Adobe After Effects
Similar vulnerabilities were also fixed in Adobe After Effects for Windows and macOS.
The company recommends that users download the Adobe After Effects 17.1.3to stay safe.
| Vulnerability Category | Vulnerability Impact | Severity | CVE Numbers |
| Out-of-Bounds Read | Arbitrary Code Execution | Critical | CVE-2020-24418 |
| Uncontrolled search path | Arbitrary Code Execution | Critical | CVE-2020-24419 |
APSB20-61 Security updates for Adobe Animate
Adobe has fixed several security in Adobe Animate for Windows and macOS. The updated version is Adobe Animate 21.0.
| Vulnerability Category | Vulnerability Impact | Severity | CVE Numbers |
| Double free | Arbitrary code execution | Critical | CVE-2020-9747 |
| Stack-based buffer overflow | Arbitrary code execution | Critical | CVE-2020-9748 |
| Out-of-bounds read | Arbitrary code execution | Critical | CVE-2020-9749CVE-2020-9750 |
APSB20-60 Security Updates for Marketo
The company fixed a Cross-site Scripting (XSS) vulnerability in the Marketo Sales Insight package, which could lead to JavaScript execution in the browser.
Users must download the Marketo Sales Insight Salesforce package 1.4357.
| Vulnerability Category | Vulnerability Impact | Severity | CVE numbers |
| Cross-site Scripting (stored) | JavaScript execution in the browser | Important | CVE-2020-24416 |
APSB20-55 Security updates for Adobe Dreamweaver
A vulnerability has been found in Adobe Dreamweaver 20.2 and earlier versions. The vulnerability could allow elevation of privilege on Windows and macOS systems.
Users should install the Dreamweaver 21.0 to stay safe.
| Vulnerability Category | Vulnerability Impact | Severity | CVE Numbers |
|---|---|---|---|
| Uncontrolled Search Path Element | Privilege Escalation | Important | CVE-2020-24425 |
APSB20-53 Security Updates for Adobe Illustrator
Finally, Adobe released security updates for Adobe Illustrator 2020 24.2 and earlier versions to address critical vulnerabilities that could allow attackers to execute code.
Users should update their systems to Illustrator 2020 version 25.0.
| Vulnerability Category | Vulnerability Impact | Severity | CVE Numbers |
| Out-of-Bounds Read | Arbitrary code execution | Critical | CVE-2020-24409CVE-2020-24410 |
| Out-of-Bounds Write | Arbitrary code execution | Critical | CVE-2020-24411 |
| Memory Corruption | Arbitrary Code Execution | Critical | CVE-2020-24412CVE-2020-24413CVE-2020-24414CVE-2020-24415 |
Source: Bleeping Computer
