Adobe releases a new set of out-of
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-24409 | Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing crafted PDF files. Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing crafted PDF files. This could result in a read past the end of an allocated memory structure, potentially resulting in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit. NVD description · AI analysis pending | 7.8 | 5% |
| — | ||
| CVE-2020-24416 | Marketo Sales Insight plugin version 1.4355 (and earlier) is affected by a blind stored Cross-Site Scripting (XSS) vulnerability that could be abused by an atta Marketo Sales Insight plugin version 1.4355 (and earlier) is affected by a blind stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. NVD description · AI analysis pending | 6.1 | 2% |
| — | ||
| CVE-2020-24418 +1 in the same advisory: …24419 | Adobe After Effects version 17.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted .aepx file, which could result in a r Adobe After Effects version 17.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted .aepx file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. This vulnerability requires user interaction to exploit. NVD description · AI analysis pending | 7.8 | 3% |
| — | ||
| CVE-2020-24421 | Adobe InDesign version 15.1.2 (and earlier) is affected by a NULL pointer dereference bug that occurs when handling a malformed .indd file. Adobe InDesign version 15.1.2 (and earlier) is affected by a NULL pointer dereference bug that occurs when handling a malformed .indd file. The impact is limited to causing a denial-of-service of the client application. User interaction is required to exploit this issue. NVD description · AI analysis pending | 5.5 | 2% |
| — | ||
| CVE-2020-24425 | Dreamweaver version 20.2 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. Dreamweaver version 20.2 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. Successful exploitation could result in a local user with permissions to write to the file system running system commands with administrator privileges. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2020-9748 | Adobe Animate version 20.5 (and earlier) is affected by a stack overflow vulnerability, which could lead to arbitrary code execution in the context of the curre Adobe Animate version 20.5 (and earlier) is affected by a stack overflow vulnerability, which could lead to arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted .fla file in Animate. NVD description · AI analysis pending | 7.8 | 6% |
| — |
Full article422 words · extracted from securityaffairs.com · click to collapse

Adobe has released a second out-of-band security update to address critical vulnerabilities affecting several products.
Adobe has released a second out-of-band security update to fix critical vulnerabilities that impact numerous products of the IT giant.
The flaws impact Adobe Illustrator, Dreamweaver, Marketo, Animate, After Effects, Photoshop, Premiere Pro, Media Encoder, InDesign, and the Creative Cloud desktop application on Windows and macOS machines.
Adobe has released seven critical vulnerabilities in Illustrator, including memory corruption and out of bounds read/write issues that can lead to arbitrary code execution.
Below the vulnerability details:
| Vulnerability Category | Vulnerability Impact | Severity | CVE Numbers |
| Out-of-Bounds Read | Arbitrary code execution | Critical | CVE-2020-24409 CVE-2020-24410 |
| Out-of-Bounds Write | Arbitrary code execution | Critical | CVE-2020-24411 |
| Memory Corruption | Arbitrary Code Execution | Critical | CVE-2020-24412 CVE-2020-24413 CVE-2020-24414 CVE-2020-24415 |
Adobe has addressed an “important” uncontrolled search path element security flaw in Dreamweaver which could be exploited by attackers to escalate privilege.
| Vulnerability Category | Vulnerability Impact | Severity | CVE Numbers |
|---|---|---|---|
| Uncontrolled Search Path Element | Privilege Escalation | Important | CVE-2020-24425 |
The company fixed four critical vulnerabilities in Animate, they are out-of-bounds read, stack overflow, and double-free flaws that can result in arbitrary code execution.
| Vulnerability Category | Vulnerability Impact | Severity | CVE Numbers |
| Double-free | Arbitrary code execution | Critical | CVE-2020-9747 |
| Stack-based buffer overflow | Arbitrary code execution | Critical | CVE-2020-9748 |
| Out-of-bounds read | Arbitrary code execution | Critical | CVE-2020-9749 CVE-2020-9750 |
Adobe addressed an “important” XSS issue impacting the Marketo Sales Insight Salesforce package that could have been weaponized to deploy malicious JavaScript in a browser session.
| Vulnerability Category | Vulnerability Impact | Severity | CVE numbers |
| Cross-site Scripting (stored) | JavaScript execution in the browser | Important | CVE-2020-24416 |
The company addressed
Vulnerability details
| Vulnerability Category | Vulnerability Impact | Severity | CVE Numbers |
| Out-of-Bounds Read | Arbitrary Code Execution | Critical | CVE-2020-24418 |
| Uncontrolled search path | Arbitrary Code Execution | Critical | CVE-2020-24419 |
Adobe addressed a single out-of-bounds read and an uncontrolled search path critial flaws in After Effects that could lead to the execution of malicious code are now patched.
| Vulnerability Category | Vulnerability Impact | Severity | CVE Numbers |
| Out-of-Bounds Read | Arbitrary Code Execution | Critical | CVE-2020-24418 |
| Uncontrolled search path | Arbitrary Code Execution | Critical | CVE-2020-24419 |
Adobe has fixed a critical memory corruption flaw in InDesign that could also be exploited to execute arbitrary code.
| Vulnerability Category | Vulnerability Impact | Severity | CVE Number |
|---|---|---|---|
| Memory Corruption | Arbitrary Code Execution | Critical | CVE-2020-24421 |
The company also fixed other critical uncontrolled search path issues in Photoshop, Premiere Pro, Media Encoder, and Creative Cloud installer for desktop.
Last week, Adobe released a separate set of out-of-band security patches affecting the Magento platform.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, code execution)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/109833/security/adobe-out-of-band-patches.html