ZeroHour
Security Affairspublished ()ingested @securityaffairs

Adobe addressed critical bugs in Illustrator, After Effects Software

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-23187
Adobe Illustrator version 26.0.3 (and earlier) is affected by a buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting

Adobe Illustrator version 26.0.3 (and earlier) is affected by a buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file in Illustrator.

NVD description · AI analysis pending
7.84%
  • adobe illustrator
CVE-2022-24090
Adobe Photoshop versions 23.1.1 (and earlier) and 22.5.5 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sens

Adobe Photoshop versions 23.1.1 (and earlier) and 22.5.5 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD description · AI analysis pending
5.52%
  • adobe photoshop
CVE-2022-24094
+3 in the same advisory: …24095 …24096 …24097
Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitr

Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD description · AI analysis pending
7.84%
  • adobe after effects
Full article217 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 15, 2023

Adobe Patch Tuesday addressed multiple vulnerabilities, including critical issues that expose Windows and macOS to hack.

Adobe released security updates to address multiple vulnerabilities impacting Photoshop, Illustrator and After Effects for both Windows and macOS users.

Adobe addressed four critical issues (CVE-2022-24094, CVE-2022-24095, CVE-2022-24096, and CVE-2022-24097) affecting the After Effects products, successful exploitation could lead to arbitrary code execution in the context of the current user.    

Below is the list of the issues:

The software giant also addressed a critical buffer overflow issue, tracked as CVE-2022-23187, in Illustrator, that can lead to arbitrary code execution. The flaw was reported by Kushal Arvind Shah of Fortinet’s FortiGuard Labs and impacts both Windows and macOS versions of Illustrator 26.0.3 and earlier versions.

The company also fixed an important-severity flaw, tracked as CVE-2022-24090, in the Photoshop software. The successful exploitation of the flaw could lead to memory leak in the context of the current user.   

The good news is that the company was not aware of any exploits in the wild for the above vulnerabilities.

Microsoft also published its Patch Tuesday security updates for February 2023 that addressed 75 flaws, including three actively exploited zero-day bugs.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Patch Tuesday)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/142280/security/adobe-critical-bugs-illustrator-after-effects-software.html