HomeSecurityAdobe: Critical zero-days threaten Acrobat and Reader

Adobe: Critical zero-days threaten Acrobat and Reader

Adobe has released security updates to fix a zero-day vulnerability in Acrobat and Reader, which has been flagged as a vulnerability that is being exploited in attacks.

See also: CISA: Federal agencies must immediately update Adobe ColdFusion servers
Adobe

Although more information about the attacks has not yet been revealed, it is known that the zero-day affects both Windows and macOS.

"Adobe is aware that CVE-2023-26369 has been exploited in limited attacks targeting Adobe Acrobat and Reader," said in a recently published security advisory.

The critical flaw is known as CVE-2023-26369 and could allow malicious actors to execute code after successfully exploiting an out-of-bounds logging vulnerability. While malicious actors can exploit this weakness in simple attacks without requiring privileges, the flaw can only be exploited by local attackers and also requires user interaction, according to the CVSS v3.1 score. CVE-2023-26369 has been classified by Adobe as high priority, and the company strongly recommends that administrators install the update as soon as possible, ideally within 72 hours.

See also: Adobe: Emergency patch fixes ColdFusion zero-day
zero day

Adobe has addressed more security issues that could allow attackers to gain arbitrary access to systems running unpatched Adobe Connect and Adobe Experience Manager. The Connect (CVE-2023-29305 and CVE-2023-29306) and Experience Manager (CVE-2023-38214 and CVE-2023-38215) vulnerabilities, which were recently patched, can be exploited to perform cross-site scripting (XSS) attacks.

Cookies can be used to access information such as session tokens and other sensitive data stored by targets' web browsers. In July, Adobe released an urgent security update for ColdFusion to address a zero-day vulnerability (CVE-2023-38205) that is exploited in limited attacks.

A few days later, CISA issued instructions to federal agencies to protect Adobe ColdFusion servers on their networks from an active security vulnerability by August 10.

See also: Adobe: Firefly's Generative Fill is coming to Photoshop

Adobe is a global software company based in California, best known for producing the Adobe Creative Cloud suite of software, which includes products such as Adobe Photoshop, Illustrator, After Effects, and Premiere Pro. However, despite its success in the software sector, the company regularly faces security challenges, as evidenced by recent news of zero-day vulnerabilities in its Adobe Acrobat and Reader products.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS