Risk Management

Adobe Patches Critical Flaws in Enterprise Products

Patch Tuesday: Adobe ships a hefty batch of security updates to fix critical-severity vulnerabilities in multiple enterprise-facing products.

Adobe Acrobat vulnerability exploited

Software maker Adobe on Tuesday released a hefty batch of security updates to fix critical-severity vulnerabilities in multiple enterprise-facing products.

The Patch Tuesday rollout contains fixes for code execution flaws in the oft-targeted Adobe ColdFusion, Adobe Premiere Pro, Adobe Bridge and Adobe Lightroom.

The San Jose, Calif. company called urgent attention to a mega-update for its Adobe Experience Manager software, documenting at least 46 vulnerabilities that expose users to arbitrary code execution and security feature bypass.

The company’s security incident response team also flagged a critical-level bug in the Adobe ColdFusion software for urgent attention, warning that successful exploitation could lead to arbitrary file system read. 

Adobe said the ColdFusion patch is available ColdFusion versions 2023 and 2021 on all platforms. 

The popular Adobe Premiere Pro digital editing software was also updated to fix a pair of code execution bugs that affect users on both Windows and macOS machines.

Adobe also pushed fixes for code execution and memory leak issues in Adobe Bridge, a critical flaw affecting Adobe Lightroom for macOS and multiple serious issues in Adobe Animate (all platforms).

The company said it was not aware of any exploits in the wild for any of the issues addressed this month.

Advertisement. Scroll to continue reading.

Related: Siemens Ruggedcom Devices Impacted by 45 Fortinet Vulnerabilities 

Related: Google Paid Out $10 Million via Bug Bounty Programs in 2023

Related: Cisco Patches High-Severity Vulnerabilities in VPN Product

Related: Microsoft Says Russians Stole Source Code After Spying on Emails

Related Content

Application Security

Adobe is providing incentives for bug bounty hackers to report security flaws in its implementation of Content Credentials and Adobe Firefly.

Cloud Security

Patch Tuesday: Microsoft warns that unauthenticated hackers can take complete control of Azure Kubernetes clusters.

Malware & Threats

Adobe calls attention to a pair of code execution bugs in Adobe Commerce and Magento Open Source, a product used to manage online stories.

Security Architecture

Microsoft ships patches for at least 60 security vulnerabilities in the Windows ecosystem and warned of remote code execution risks.

Application Security

Enterprise software maker SAP documents multiple critical-severity issues and warns of risk of command injection attacks.

Endpoint Security

AMD and Intel patch dozens of vulnerabilities on February 2024 Patch Tuesday, including multiple high-severity bugs.

Malware & Threats

Patch Tuesday: Microsoft pushes a massive batch of security-themed updates and calls urgent attention to exploits bypassing security features.

Vulnerabilities

Intel, AMD, Zoom and Splunk released security advisories on Patch Tuesday to inform customers about vulnerabilities found in their products.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version