Adobe has released security updates that cover updates for Adobe Acrobat and Reader, ColdFusion and Creative Cloud Desktop Application.
The security updates cover 75 vulnerabilities out of them 71 resides with the Adobe Acrobat and Reader itself.
With the security update adobe patched 71 vulnerabilities Adobe Acrobat and Reader for Windows and MacOS. The updates cover critical and important vulnerabilities.
An attacker could exploit the vulnerability to run arbitrary code on the infected machine in the context of the current user.
Acrobat DC 2019.010.20069 and earlier versions
Acrobat Reader DC 2019.010.20069 and earlier versions
Acrobat 2017 Classic 2017 2017.011.30113 and earlier version
Acrobat Reader 2017 Classic 2017 2017.011.30113 and earlier version
Acrobat DC Classic 2015 2015.006.30464 and earlier versions
Acrobat Reader DC Classic 2015 2015.006.30464 and earlier version
Users are recommended to update with the following versions.
Acrobat DC 2019.010.20091
Acrobat Reader DC 2019.010.20091
Acrobat 2017 Classic 2017 2017.011.30120
Acrobat Reader DC 2017 Classic 2017 2017.011.30120
Acrobat DC Classic 2015 2015.006.30475
Acrobat Reader DC Classic 2015 2015.006.30475
You can find the complete vulnerability details and CVE in the Adobe advisory.
The updates cover ColdFusion versions 2018, 2016 and 11, successful exploitation of the vulnerability leads to arbitrary code execution.
ColdFusion 2018 Update 1 and earlier versions
ColdFusion 2016 Update 7 and earlier versions
ColdFusion 11 Update 15 and earlier versions
Newest versions
ColdFusion 2018 Update 2
ColdFusion 2016 Update 8
ColdFusion 11 Update 16
The security update for Creative Cloud Desktop Application installer for Windows resolves the insecure library loading vulnerability in the installer that could lead to privilege escalation, reads the advisory.
Affected version
Creative Cloud Desktop Application (installer) 4.7.0.400 and earlier versions
Fixed Version
Creative Cloud Desktop Application (installer) 4.8.0.410
Adobe Released Security Patches for Digital Editions and Connect
87 Vulnerabilities Fixed With Adobe December Security Update for Acrobat and Reader
Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting victims…
The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ advanced…
A significant XSS vulnerability was recently uncovered in Microsoft’s Bing.com, potentially allowing attackers to execute…
Meta has announced the removal of over 2 million accounts connected to malicious activities, including…
Critical security vulnerability has been identified in Veritas Enterprise Vault, a widely-used archiving and content…
A critical security vulnerability has been disclosed in the popular file archiving tool 7-Zip, allowing…