Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
ID: 8947723d-b4d6-59bd-acf8-c1978d2a56e4
STIX ID: report--8947723d-b4d6-59bd-acf8-c1978d2a56e4
Feed Name: CISecurity.org Advisories
Multiple vulnerabilities have been disclosed in Adobe products—including Acrobat/Reader, Illustrator, InDesign, and various Substance 3D applications—covering many CVEs and issues (use-after-free, buffer overflows, out-of-bounds read/write, NULL pointer dereference, untrusted search path). The advisory states that the most severe flaws could enable arbitrary code execution as the logged-on user, allowing attackers to install programs, access or modify data, or create accounts; impact varies with user privileges. The report maps the activity to the Execution tactic and the Exploitation for Client Execution technique (T1203).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
