HomeSecurityAdobe: Fixes vulnerabilities affecting Windows/macOS apps

Adobe: Fixes vulnerabilities affecting Windows/macOS apps

Adobe has released updates security to address vulnerabilities affecting many of its Windows and macOS products . These vulnerabilities could allow attackers to execute code on devices running vulnerable versions of the software .

Adobe: Fixes critical vulnerabilities affecting Windows/macOS

The vulnerabilities that Adobe is patching are located in: Adobe Creative Cloud Desktop Application, Adobe InDesign, Adobe Media Encoder, Adobe Premiere Pro, Adobe Photoshop, Adobe After Effects, Adobe Animate, Adobe Dreamweaver, Adobe Illustrator and Marketo.

In total, the company patched 20 vulnerabilities. 18 of them have been rated “critical” and two “serious.”

Adobe urges all users of vulnerable products to update systems to protect themselves from potential attacks.

APSB20-68 Security Update for Adobe Creative Cloud Desktop Application

Adobe has released an update for Adobe InDesign that fixes a vulnerability in the Creative Cloud Desktop Application installer for Windows. The vulnerability could lead to malicious code execution.

Windows users need to install Creative Cloud DesktopApplication 5.3 (old installer) or 2.2 (new installer) to fix this critical error.

Vulnerability CategoryVulnerability ImpactSeverityCVE Numbers
Uncontrolled Search PathArbitrary Code ExecutionCriticalCVE-2020-24422

APSB20-66 Security Update for Adobe InDesign

Adobe also fixed a critical memory error in Adobe InDesign, which could also lead to code execution on Windows systems.

Users are urged to install Adobe InDesign version 16.0 as soon as possible.

Vulnerability CategoryVulnerability ImpactSeverityCVE Number
Memory CorruptionArbitrary Code ExecutionCriticalCVE-2020-24421

APSB20-65 Security updates for Adobe Media Encoder

The new security update also fixes a vulnerability in Adobe Media Encoder, which causes the same problems as the first vulnerability (in the Creative Cloud Desktop Application).

Windows users need to install Adobe Media Encoder version 14.5 .

Vulnerability CategoryVulnerability ImpactSeverityCVE Numbers
Uncontrolled Search PathArbitrary Code ExecutionCritical   CVE-2020-24423

APSB20-64 Security updates for Adobe Premiere Pro

Another vulnerability that allows code execution was found in Adobe Premiere Pro 14.4 and earlier versions.

Windows and macOS users should get the Adobe Premiere Pro 14.5 update.

Vulnerability CategoryVulnerability ImpactSeverityCVE Numbers
Uncontrolled search path elementArbitrary Code Execution CriticalCVE-2020-24424

APSB20-63 Security Updates for Adobe Photoshop

The company also fixed a similar vulnerability in Adobe Photoshop.

Windows and macOS users should get the Photoshop 21.2.3 update or Photoshop 2021 22.0 to fix this critical vulnerability.

Vulnerability CategoryVulnerability ImpactSeverityCVE Number
Uncontrolled search path elementArbitrary code execution   Critical CVE-2020-24420

APSB20-62 Security updates for Adobe After Effects

Similar vulnerabilities were also fixed in Adobe After Effects for Windows and macOS.

The company recommends that users download the Adobe After Effects 17.1.3to stay safe.

Vulnerability CategoryVulnerability ImpactSeverityCVE Numbers
Out-of-Bounds ReadArbitrary Code Execution    Critical  CVE-2020-24418
Uncontrolled search pathArbitrary Code Execution      CriticalCVE-2020-24419

APSB20-61 Security updates for Adobe Animate

Adobe has fixed several security in Adobe Animate for Windows and macOS. The updated version is Adobe Animate 21.0.

Vulnerability CategoryVulnerability ImpactSeverityCVE Numbers
Double freeArbitrary code executionCriticalCVE-2020-9747
Stack-based buffer overflowArbitrary code executionCriticalCVE-2020-9748
Out-of-bounds readArbitrary code executionCriticalCVE-2020-9749CVE-2020-9750

APSB20-60 Security Updates for Marketo

The company fixed a Cross-site Scripting (XSS) vulnerability in the Marketo Sales Insight package, which could lead to JavaScript execution in the browser.

Users must download the Marketo Sales Insight Salesforce package 1.4357.

Vulnerability CategoryVulnerability ImpactSeverityCVE numbers
Cross-site Scripting (stored)JavaScript execution in the browserImportantCVE-2020-24416

APSB20-55 Security updates for Adobe Dreamweaver

A vulnerability has been found in Adobe Dreamweaver 20.2 and earlier versions. The vulnerability could allow elevation of privilege on Windows and macOS systems.

Users should install the Dreamweaver 21.0 to stay safe.

Vulnerability CategoryVulnerability ImpactSeverityCVE Numbers
Uncontrolled Search Path ElementPrivilege Escalation ImportantCVE-2020-24425

APSB20-53 Security Updates for Adobe Illustrator

Finally, Adobe released security updates for Adobe Illustrator 2020 24.2 and earlier versions to address critical vulnerabilities that could allow attackers to execute code.

Users should update their systems to Illustrator 2020 version 25.0.

Vulnerability CategoryVulnerability ImpactSeverityCVE Numbers
Out-of-Bounds ReadArbitrary code execution CriticalCVE-2020-24409CVE-2020-24410
Out-of-Bounds WriteArbitrary code execution 

 
Critical

 
CVE-2020-24411
Memory CorruptionArbitrary Code ExecutionCriticalCVE-2020-24412CVE-2020-24413CVE-2020-24414CVE-2020-24415

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS