Wednesday, July 22, 2020

Adobe Prelude Update Available

Adobe have released an update to patch critical vulnerabilities (CVE-2020-9677, CVE-2020-9678, CVE-2020-9679, CVE-2020-9680) in their Prelude application. The vulnerabilities may allow arbitrary code execution in vulnerable system in the context of the current user.

Affected versions:
Adobe Prelude earlier than 9.0.1 version

More information in the related security bulletin here.

New Version Of Adobe Photoshop Available

Adobe have released new versions of Adobe Photoshop for Windows and Macintosh. These updates resolve multiple vulnerabilities (CVE-2020-9683, CVE-2020-9684, CVE-2020-9685, CVE-2020-9686, CVE-2020-9687) which could lead to arbitrary code execution in the context of the current user.

Affected versions:
Adobe Photoshop CC 20.0.9 and earlier versions (Windows)
Adobe Photoshop CC 21.2 and earlier versions (Windows)

Solution:
Update to Adobe Photoshop CC 20.0.10 or 21.2.1 version

Instructions for updating are given in related security bulletin.

Adobe Bridge Updated

Adobe have updated their Bridge to new version. This new version resolves three critical vulnerabilities (CVE-2020-9674, CVE-2020-9675, CVE-2020-9676) which may allow execution of arbitrary code.

Affected versions:
- Adobe Bridge 10.0.3 and earlier versions for Windows

More information can be read from Adobe's security bulletin.

Adobe Download Manager Updated

Adobe has released updated version of their Download Manager for Windows. The new version fixes one critical (CVE-2020-9688) categorized vulnerability that could lead to arbitrary code execution.

Affected is version 2.0.0.518. The new version 2.0.0.529 is available for Adobe Reader for Windows here and for Adobe Flash Player for Windows here.

More information from the Adobe's security advisory.

Adobe ColdFusion Updated

Adobe have released updated version of ColdFusion web application development platform. This fix resolves two important categorized (CVE-2020-9672, CVE-2020-9673) vulnerabilities that could lead to privilege escalation.

Affected versions:
- ColdFusion (2018 release): update 9 and earlier versions
- ColdFusion (2016 release): update 15 and earlier versions

More information can be read from Adobe's security bulletin.

Adobe Genuine Service Updated

Adobe have released security updates to fix vulnerabilities (CVE-2020-9667, CVE-2020-9668, CVE-2020-9681) in their Genuine Service. The vulnerabilities could lead to privilege escalation in the context of the current user.

Affected versions:
Adobe Genuine Service earlier than 7.1 on Windows and macOS


Adobe Genuine Service has a self-update mechanism that runs automatically at a regular interval when the host is connected to the internet.


More information about fixed vulnerability can be read from Adobe's security bulletin.

Adobe Media Encoder Updated

Adobe have released an updated versions of their Media Encoder. The new versions fix two vulnerabilities categorized as critical (CVE-2020-9646, CVE-2020-9650) and one as important (CVE-2020-9649). By exploiting the critical vulnerabilities an attacker may be able to execute arbitrary code in the context of the current user.

Affected versions:
- Adobe Media Encoder versions earlier than 14.3

More information in security bulletin.