Adobe Security Advisory for December Security Updates

Adobe Security Advisory for December Security Updates

December 29, 2019 | Adeline Zhang

Overview

On December 11, local time, Adobe officially released a December security update that fixes multiple vulnerabilities in Adobe’s many products, including Adobe Photoshop CC, Adobe Acrobat and Reader, Brackets, and Adobe ColdFusion.

For details, visit the following link:

https://helpx.adobe.com/security.html

 Vulnerability Description

Adobe Photoshop CC

Adobe has released an Adobe Photoshop CC security update that fixes two security vulnerabilities.

Vulnerability details are as follows:

Vulnerability Category Vulnerability Impact Severity Level CVE ID
Memory corruption Arbitrary code execution Critical CVE-2019-8253
Memory corruption Arbitrary code execution Critical CVE-2019-8254

For details on the vulnerability impact and remediation, refer to the security bulletin at the following link:

https://helpx.adobe.com/security/products/photoshop/apsb19-56.html

Brackets

Adobe has released a Brackets security update that fixes one security vulnerability.

Vulnerability details are as follows:

Vulnerability Category Vulnerability Impact Severity Level CVE ID
Command injection Arbitrary code execution Critical CVE-2019-8255

For details on the vulnerability impact and remediation, refer to the security bulletin at the following link:

https://helpx.adobe.com/security/products/brackets/apsb19-57.html

Adobe ColdFusion

Adobe has released the Adobe ColdFusion security update that fixes one security vulnerability.

Vulnerability details are as follows:

Vulnerability Category Vulnerability Impact Severity Level CVE ID
Default installation path Elevation of authority Important CVE-2019-8256

For details on the vulnerability impact and remediation, refer to the security bulletin at the following link:

https://helpx.adobe.com/security/products/coldfusion/apsb19-58.html

Adobe Acrobat and Reader

Adobe has released a security update for Adobe Acrobat and Reader that fixes 21 security vulnerabilities.

Vulnerability details are as follows:

Vulnerability Category Vulnerability Impact Severity Level CVE ID
Out-of-bounds read Information leakage Important CVE-2019-16449

CVE-2019-16456

CVE-2019-16457

CVE-2019-16458

CVE-2019-16461

CVE-2019-16465

Out-of-bounds write  Arbitrary code execution Critical CVE-2019-16450

CVE-2019-16454

Reuse after release   Arbitrary code execution Critical CVE-2019-16445

CVE-2019-16448

CVE-2019-16452

CVE-2019-16459

CVE-2019-16464

Heap overflow Arbitrary code execution Critical CVE-2019-16451
Buffer error Arbitrary code execution Critical CVE-2019-16462
Untrusted pointer error Arbitrary code execution Critical CVE-2019-16446

CVE-2019-16455

CVE-2019-16460

CVE-2019-16463

Directory permission elevation Elevation of authority Important CVE-2019-16444
Safe bypass Arbitrary code execution Critical CVE-2019-16453

For details on the vulnerability impact and remediation, refer to the security bulletin at the following link:

https://helpx.adobe.com/security/products/acrobat/apsb19-55.html

Solution

Adobe has officially released security updates to fix the preceding vulnerabilities. Users are advised to upgrade their installation to the latest version as soon as possible.

For vulnerability details and remediation, please visit the preceding security bulletin links.

Statement

This advisory is only used to describe a potential risk. NSFOCUS does not provide any commitment or promise on this advisory. NSFOCUS and the author will not bear any liability for any direct and/or indirect consequences and losses caused by transmitting and/or using this advisory. NSFOCUS reserves all the rights to modify and interpret this advisory. Please include this statement paragraph when reproducing or transferring this advisory. Do not modify this advisory, add/delete any information to/from it, or use this advisory for commercial purposes without permission from NSFOCUS.

About NSFOCUS

NSFOCUS, Inc., a global network and cyber security leader, protects enterprises and carriers from advanced cyber attacks. The company’s Intelligent Hybrid Security strategy utilizes both cloud and on-premises security platforms, built on a foundation of real-time global threat intelligence, to provide multi-layered, unified and dynamic protection against advanced cyber attacks.

NSFOCUS works with Fortune Global 500 companies, including four of the world’s five largest financial institutions, organizations in insurance, retail, healthcare, critical infrastructure industries as well as government agencies. NSFOCUS has technology and channel partners in more than 60 countries, is a member of both the Microsoft Active Protections Program (MAPP), and the Cloud Security Alliance (CSA).

A wholly owned subsidiary of NSFOCUS Information Technology Co. Ltd., the company has operations in the Americas, Europe, the Middle East and Asia Pacific.