2022年4月13日星期三

Adobe Monthly Security Update (April 2022)

Release Date: 13 Apr 2022

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
Adobe CommerceMedium Risk Medium RiskRemote Code Execution APSB22-13
Adobe Acrobat and ReaderMedium Risk Medium RiskInformation Disclosure
Remote Code Execution
Elevation of Privilege
Security Restriction Bypass
 APSB22-16
Adobe After EffectsMedium Risk Medium RiskRemote Code Execution APSB22-19
Adobe PhotoshopMedium Risk Medium RiskRemote Code Execution APSB22-20

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 4

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Remote Code Execution
  • Information Disclosure
  • Elevation of Privilege
  • Security Restriction Bypass

System / Technologies affected

  • Adobe Commerce 2.4.3-p1 and earlier versions
  • Adobe Commerce 2.3.7-p2 and earlier versions
  • Magento Open Source 2.4.3-p1 and earlier versions
  • Magento Open Source 2.3.7-p2 and earlier versions
  • Acrobat DC 22.001.20085 and earlier versions
  • Acrobat Reader DC 22.001.20085 and earlier versions
  • Acrobat 2020 20.005.30314 and earlier versions
  • Acrobat Reader 2020 20.005.30314 and earlier versions
  • Acrobat 2017 17.012.30205 and earlier versions
  • Acrobat Reader 2017 17.012.30205  and earlier versions
  • Adobe After Effects 22.2.1 and earlier versions
  • Adobe After Effects 18.4.5 and earlier versions
  • Photoshop 2021 22.5.6 and earlier versions
  • Photoshop 2022 23.2.2 and earlier versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update

Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

思科產品多個漏洞

思科產品多個漏洞 發佈日期: 2025年05月09日 風險: 中度風險 類型: 保安軟件及應用設備 - 保安軟件及應用設備 於思科產品發現多個漏...