Monday, February 14, 2022

Mozilla Thunderbird Updated

Mozilla have released updated version of their Thunderbird email client containing some fixes to security vulnerabilities.

Affected versions:
- Mozilla Thunderbird earlier than 91.6 (advisory)

Fresh version can be obtained via inbuilt updater or by downloading from the product site.

Mozilla Firefox Updated

Mozilla have released updated versions of their Firefox web browser. New versions fix security vulnerabilities.

Affected versions:
-Mozilla Firefox earlier than 97 (advisory)
-Mozilla Firefox ESR 91.x earlier than 91.6 (advisory)

Fresh version can be obtained via inbuilt updater or by downloading (latest version) from the product site.

Adobe Commerce Vulnerabilities Fixed

Adobe has released updates for Adobe Commerce and Magento Open Source editions. The new versions fix a critical vulnerablity (CVE-2022-24086) which may lead to arbitrary code execution.

Affected versions
Adobe Commerce 2.4.3-p1 and earlier versions
Adobe Commerce 2.3.7-p2 and earlier versions
Magento Open Source 2.4.3-p1 and earlier versions
Magento Open Source 2.3.7-p2 and earlier versions

More information in the correspondent security bulletin.

Adobe Creative Cloud Desktop Application Updated

Adobe has released a security update to fix a critical vulnerability (CVE-2022-23202) in their Creative Cloud Desktop Application for macOS. The vulnerability may allow arbitrary code execution in the context of the current user.

Affected versions:
Creative Cloud Desktop Application (Installer) 2.7.0.13 and earlier versions for Windows

More information can be read from Adobe's security bulletin.

Adobe After Effects Updated

Adobe has released an update to patch a critical vulnerability (CVE-2022-23200) in After Effects application. The vulnerability could allow arbitrary code execution in the context of the current user.

Affected versions:
- Adobe After Effects earlier than 22.2 version on Windows and macOS
- Adobe After Effects earlier than 18.4.4 version on Windows and macOS

More information in security bulletin.

Adobe Photoshop Vulnerability Fixed

Adobe have released new versions of Adobe Photoshop for Windows and macOS. These updates resolve a security vulnerability (CVE-2022-23203) which could lead to arbitrary code execution in the context of the current user.

Affected versions on Windows and macOS:
- Adobe Photoshop 2022 versions 23.x earlier than 23.1.1
- Adobe Photoshop 2021 versions 22.x earlier than 22.5.5

Instructions for updating are given in related security bulletin.

Adobe Illustrator Updated

Adobe have released an updated version of their Adobe Illustrator for Windows and macOS. The new version fixes bunch of security vulnerabilities of which some may allow arbitrary code execution.

Affected versions
Illustrator 2022 26.0.2 and earlier versions
Illustrator 2021 25.4.3 and earlier versions

Solution
Update Illustrator 2022 to 26.0.3 (or newer) version
Update Illustrator 2021 to 25.4.4 (or newer) version


More information in the correspondent security bulletin.

Adobe Premiere Rush Update Released

Adobe has released an update to patch a vulnerability in Premiere Rush application. The vulnerability may allow privilege escalation (CVE-2022-23204).

Affected versions:
Adobe Premiere Rush earlier than 2.3 version for Windows

More information in the related security bulletin here.

Wednesday, February 9, 2022

Microsoft Security Updates For February 2022

Microsoft have released security updates for February 2022.

Release notes of the updates can be viewed here.

Saturday, February 5, 2022

Google Chrome updated

Google have released version 98.0.4758.80/81/82 for Windows and 98.0.4758.80 macOS and Linux. In addition to other changes the new version contains fixes to 27 security vulnerabilities.

More information can be read from Google Chrome releases blog.

Friday, February 4, 2022

Vulnerability in VMware Cloud Foundation

VMware have released updated versions of their virtualization software patching a security vulnerability (CVE-2022-22939).

Affected versions:
-VMware Cloud Foundation (NSX-T) 4.x earlier than 4.3.1.1
-VMware Cloud Foundation (NSX-T) 3.x (patch pending, check back the advisory)

More information in VMware advisory here.

Foxit PDF Reader And Foxit PDF Editor Updated

Foxit Software has released version 11.2.1 of their Foxit PDF Reader and Foxit PDF Editor software for Windows. The new versions contain fixes for security vulnerabilities that if exploited may allow an attacker to execute arbitrary code in target system.

Affected versions:
Foxit PDF Reader (previously named Foxit Reader) 11.1.0.52543 and earlier (Windows)
Foxit PDF Editor (previously named Foxit PhantomPDF) 11.2.0.53415 and all previous 11.x versions, 10.1.6.37749 and earlier (Windows)

More information can be read here.