Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
ID: 289b8944-f130-5d41-9401-aa5623c15700
STIX ID: report--289b8944-f130-5d41-9401-aa5623c15700
Feed Name: CISecurity.org Advisories
Multiple vulnerabilities affecting several Adobe products (ColdFusion, Commerce, Lightroom, Content Credentials SDK, Campaign Classic) were disclosed, including OS command injection, eval injection, improper authorization, XSS, path traversal, deserialization, buffer overflows, integer overflows/underflows, SSRF and other flaws (numerous CVEs listed). The most severe issues could allow arbitrary code execution in the context of the logged-on user, enabling installation of programs, data access/modification, or account creation depending on user privileges; no evidence of active exploitation is provided in the report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
