Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
ID: ee5a2f58-e233-5ad6-896c-e54d74c53737
STIX ID: report--ee5a2f58-e233-5ad6-896c-e54d74c53737
Feed Name: CISecurity.org Advisories
Multiple vulnerabilities have been disclosed across numerous Adobe products (Connect, Commerce, Creative Cloud Desktop, Bridge, Animate, Experience Manager Screens, Substance 3D family, FrameMaker, Illustrator, Dimension, and Stager). The issues include memory corruption (heap/stack buffer overflows, out-of-bounds read/write, use-after-free), integer overflow, TOCTOU race condition, and multiple XSS and access control flaws (many assigned CVEs). Successful exploitation of the most severe flaws could enable arbitrary code execution under the logged-on user account, allowing program installation, data access/modification, or account creation depending on privileges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
