ZeroHour
Security Affairspublished ()ingested @securityaffairs

Adobe Patch Tuesday updates fix code execution issues in Campaign, ColdFusion, and Flash

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-7839
+2 in the same advisory: …7838 …7840
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability.

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

NVD description · AI analysis pending
9.844%
  • adobe coldfusion
CVE-2019-7845
Adobe Flash Player versions 32.0.0.192 and earlier, 32.0.0.192 and earlier, and 32.0.0.192 and earlier have an use after free vulnerability.

Adobe Flash Player versions 32.0.0.192 and earlier, 32.0.0.192 and earlier, and 32.0.0.192 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

NVD description · AI analysis pending
8.86%
  • adobe flash player
  • adobe enterprise linux desktop
  • adobe enterprise linux server
  • +1 more
CVE-2019-7850
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability.

Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.

NVD description · AI analysis pending
9.86%
  • adobe campaign
Full article312 words · extracted from securityaffairs.com · click to collapse

Adobe Patch Tuesday updates for June 2019 address several critical arbitrary code execution flaws in Flash Player, ColdFusion and Campaign products.

Adobe Patch Tuesday security updates for June 2019 address some critical arbitrary code execution vulnerabilities in Flash Player, ColdFusion and Campaign products.

Adobe fixed critical command injection, file extension blacklist bypass and deserialization vulnerabilities in ColdFusion. The vulnerabilities could lead to arbitrary code execution on vulnerable systems. Below the list of flaws in ColdFusion fixed by Adobe:

Vulnerability CategoryVulnerability ImpactSeverityCVE Numbers
File extension blacklist bypassArbitrary code executionCritical (see note below) CVE-2019-7838
Command InjectionArbitrary code executionCritical (see note below) CVE-2019-7839
Deserialization of untrusted dataArbitrary code executionCritical (see note below) CVE-2019-7840

The issues affect ColdFusion 2016, 2018 and 11.

Adobe credited Badcode of Knownsec 404 Team, Moritz Bechler of SySS GmbH, and Brenden Meeder of Booz Allen Hamilton for reporting the flaw.

Adobe also informed users that remote access to the Adobe LiveCycle Data Management feature has been disabled by default due to security risks.

Adobe Patch Tuesday security updates for June 2019 also address a critical use-after-free vulnerability (CVE-2019-7845) that could lead to arbitrary code execution. The flaw was anonymously reported via Trend Micro’s Zero Day Initiative.

“Adobe has released security updates for Adobe Flash Player for Windows, macOS, Linux and Chrome OS. These updates address a critical vulnerability in Adobe Flash Player.” reads the security advisory. “Successful exploitation could lead to arbitrary code execution in the context of the current user. ”

Finally, Adobe addressed seven types of vulnerabilities in its Campaign product, including information disclosure, arbitrary file read, and code execution issues. The most severe vulnerability, tracked as CVE-2019-7850, is a critical command injection issue that could lead to arbitrary code execution.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Adobe Patch Tuesday, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/86995/security/adobe-patch-tuesday-june-2019.html