Adobe's last scheduled security update of the year has fixed some critical vulnerabilities in Lightroom, Prelude, and Experience Manager.
The patches released on Tuesday by the giant company address four vulnerabilities, three of which are considered critical.

The first patch was issued for Adobe Lightroom, an image editing software popular with professional photographers. The vulnerability, reported as CVE-2020-24447 – described as an unchecked path element search vulnerability that leads to arbitrary code execution – affects Lightroom Classic version 10.0 and later on Windows and macOS computers.
A second critical flaw has been identified in AdobePrelude for Windows and macOS, version 9.01 and earlier. The serious vulnerability, CVE-2020-24440, is caused by an uncontrolled search path and, if exploited by attackers, could lead to “arbitrary code execution in the context of the current user,” Adobe says.
Adobe's third security advisory relates to Adobe Experience Manager (AEM) and the AEM Forms add-on across all platforms.
Two vulnerabilities have been fixed in these software packages. The first, CVE-2020-24445, is a critical bug in AEM CS and is also found in AEM 6.5.6.0/6.4.8.2/6.3.3.8 and later.
CVE-2020-24445 is a cached cross-site scripting (XSS) that can lead to arbitrary JavaScript execution in the browser.
The second security flaw, CVE-2020-24444, is a “critical” vulnerability found in the AEM Forms SP6 add-on for AEM 6.5.6.0 and the AEM Forms add-on for AEM 6.4 Service Pack 8 Cumulative Fix Pack 2 (6.4.8.2). This vulnerability is a blind server request forgery issue that can be exploited for information disclosure purposes .
Adobe thanked researcher Hou JingYi of Qihoo 360 CERT, as well as Frank Karlstrøm and Kenny Jansson of Storebrand Group, for reporting the security issues.
Adobe's November security update addressed a couple more vulnerabilities, two of which were found in its remote conferencing software Connect and one in Reader. The Connect bugs could be exploited to execute JavaScript in a browser, while the Reader issue could be used to leak information.
In Microsoft's latest update of the year, released on Tuesday, the giant company patched 58 vulnerabilities, 22 of which are remote code execution (RCE) vulnerabilities.
