ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Adobe's Year-End Update Patches 87 Flaws in Acrobat Software

criticalVulnerability exploited in the wildimportance 60CVE-2018-15982

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-15982
Use-After-Free in Adobe Flash Player Allows Arbitrary Code Execution

CVE-2018-15982 is a use-after-free flaw (CWE-416) in Adobe Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier, in which Flash frees memory that is subsequently reused, corrupting process memory. It is triggered when Flash processes crafted Flash content, most notably embedded in Microsoft Office documents, requiring a user to open or view the malicious content (CVSS attack vector is local with user interaction required). Successful exploitation gives the attacker arbitrary code execution with the privileges of the user viewing the content. Affected users include anyone running the listed Flash Player versions, including the Flash Player Installer and the Adobe-supplied Flash plugin shipped with Red Hat Enterprise Linux Desktop, Server and Workstation. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-15) with known ransomware use, a public exploit is available on Exploit-DB, and EPSS assigns a top-percentile 89.1% probability of exploitation within 30 days.

Do: Flash Player is end-of-life: per CISA's required action, remove or disconnect Flash wherever it is still in use; if Flash must remain, update beyond the affected 31.0.0.153/31.0.0.108 builds and update the flash-plugin package on Red Hat Enterprise Linux. Mitigate the known delivery vector by blocking or disabling embedded Flash (SWF) content in Microsoft Office documents and mail clients, and hunt for suspicious documents with embedded Flash given the known in-the-wild and ransomware use.

7.889% KEV ransomware PoC
  • Adobe Flash Player 31.0.0.153 and earlier, and 31.0.0.108 and earlier
  • Adobe Flash Player Installer Same affected ranges as Flash Player (31.0.0.153 and earlier / 31.0.0.108 and earlier)
  • Red Hat Enterprise Linux Desktop (Adobe-supplied flash-plugin)
  • +2 more
mass≈100M+ endpoints historically (Flash was preinstalled/bundled across most Windows desktops and shipped with Chrome and RHEL in 2018); only residual legacy…
Full article385 words · extracted from thehackernews.com · click to collapse

Swati KhandelwalDec 12, 2018

Adobe is closing out this year with its December Patch Tuesday update to address a massive number of security vulnerabilities for just its two PDF apps—more than double the number of what Microsoft patched this month for its several products.

Adobe today released patches for 87 vulnerabilities affecting its Acrobat and Reader software products for both macOS and Windows operating systems, of which 39 are rated as critical and 48 important in severity.

The security update comes less than a week after Adobe released patches for a critical zero-day vulnerability (CVE-2018-15982) in Flash Player that was actively being exploited in a targeted attack targeting a Russian state health care institution.

The critical vulnerabilities addressed today in Acrobat and Reader include three heap-overflow bugs, five out-of-bounds write flaws, two untrusted pointer dereference issues, two buffer errors, and 24 use-after-free bugs.

Upon successful exploitation, all of the above critical vulnerabilities would allow an attacker to execute arbitrary code on compromised computers.

Rest three critical-rated issues addressed this month are all security bypass issues which, if exploited, would lead to privilege escalation.

In addition to the critical bugs, Adobe patched 48 'important' security flaws in the Acrobat and Reader, including 43 are out-of-bounds read issues, four integer overflow flaws, and two security bypass issues—all of which could lead to information disclosure.

According to the company's support website, vulnerabilities rated as important, "if exploited would compromise data security, potentially allowing access to confidential data, or could compromise processing resources in a user's computer."

The company did not disclose technical details of any of the vulnerabilities, but categorized all the flaws, both critical and important, as "Priority 2," meaning that the flaws are unlikely to be exploited in the wild but are at high risk of being exploited.

"There are currently no known exploits. Based on previous experience, we do not anticipate exploits are imminent," Adobe says. "As a best practice, Adobe recommends administrators install the update soon (for example, within 30 days)."

Users of the Adobe Acrobat and Reader apps for Windows and macOS operating systems are highly recommended to update their software packages to the latest versions as soon as possible.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2018/12/adobe-acrobat-update.html