2025年10月15日星期三

Adobe Monthly Security Update (October 2025)

Adobe Monthly Security Update (October 2025)

Release Date: 15 Oct 2025

RISK: Medium Risk

TYPE: Clients - Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
Adobe ConnectMedium Risk Medium RiskCross-site Scripting
Remote Code Execution
Security Restriction Bypass
 APSB25-70
Adobe CommerceMedium Risk Medium RiskSecurity Restriction Bypass
Cross-site Scripting
Elevation of Privilege
Remote Code Execution
 APSB25-94
Adobe Creative Cloud Desktop ApplicationMedium Risk Medium RiskData Manipulation APSB25-95
Adobe BridgeMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB25-96
Adobe AnimateMedium Risk Medium Risk

Remote Code Execution

Information Disclosure

 APSB25-97
Adobe Experience Manager ScreensMedium Risk Medium RiskCross-site Scripting
Remote Code Execution
 APSB25-98
Substance 3D ViewerMedium Risk Medium RiskRemote Code Execution
Denial of Service
 APSB25-99
Substance 3D ModelerMedium Risk Medium RiskRemote Code Execution APSB25-100
Adobe FrameMakerMedium Risk Medium RiskRemote Code Execution APSB25-101
Adobe IllustratorMedium Risk Medium RiskRemote Code Execution APSB25-102
Adobe DimensionMedium Risk Medium RiskRemote Code Execution APSB25-103
Substance 3D StagerMedium Risk Medium RiskRemote Code Execution APSB25-104

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 12

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Remote Code Execution
  • Denial of Service
  • Data Manipulation
  • Security Restriction Bypass
  • Information Disclosure
  • Elevation of Privilege
  • Cross-Site Scripting

System / Technologies affected

  • Adobe Connect 12.9 and earlier versions
  • Adobe Commerce 2.4.9-alpha2 and earlier versions
  • Adobe Commerce B2B 1.5.3-alpha2 and earlier versions
  • Magento Open Source 2.4.9-alpha2 and earlier versions
  • Creative Cloud Desktop Application 6.7.0.278 and earlier versions
  • Adobe Bridge  14.1.8 (LTS) and earlier versions
  • Adobe Bridge  15.1.1 and earlier versions
  • Adobe Animate 2023 23.0.13 and earlier versions
  • Adobe Animate 2024 24.0.10 and earlier versions
  • Adobe Experience Manager (AEM) Screens AEM 6.5.22 Screens FP11.6
  • Adobe Substance 3D Viewer 0.25.2 and earlier versions
  • Adobe Substance 3D Modeler 1.22.3 and earlier versions
  • Adobe FrameMaker 2020 Release Update 9 and earlier versions
  • Adobe FrameMaker 2022 Release Update 7 and earlier versions
  • Illustrator 2025 29.7 and earlier versions
  • Illustrator 2024 28.7.9 and earlier versions
  • Adobe Dimension 4.1.4 and earlier versions
  • Adobe Substance 3D Stager 3.1.4 and earlier versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update.

Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

WatchGuard Fireware 遠端執行程式碼漏洞

WatchGuard Fireware 遠端執行程式碼漏洞 發佈日期: 2025年12月22日 風險: 極高度風險 類型: 伺服器 - 其他伺服...