Adobe August 2018 Patch Tuesday addresses 11 vulnerabilities in its products
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-12808 +1 in the same advisory: …12799 | Adobe Acrobat and Reader versions 2018.011.20055 and earlier, 2017.011.30096 and earlier, and 2015.006.30434 and earlier have an out-of-bounds write vulnerabili Adobe Acrobat and Reader versions 2018.011.20055 and earlier, 2017.011.30096 and earlier, and 2015.006.30434 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. NVD description · AI analysis pending | 9.8 group max | 8% |
| — | ||
| CVE-2018-12824 | Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. NVD description · AI analysis pending | 5.9 | 11% |
| — | ||
| CVE-2018-12825 | Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitation could lead to security mitigation bypass. NVD description · AI analysis pending | 9.8 group max | 7% |
| — |
Full article328 words · extracted from securityaffairs.com · click to collapse

Adobe released the August 2018 Patch Tuesday updates that address 11 vulnerabilities in Flash Player, the Creative Cloud Desktop Application, Experience Manager, and Acrobat and Reader.
Adobe August 2018 Patch Tuesday updates have addressed eleven vulnerabilities in eleven products, five of them in Flash Player.
Below vulnerability details:
| Vulnerability Category | Vulnerability Impact | Severity | CVE Number |
| Out-of-bounds read | Information Disclosure | Important | CVE-2018-12824 |
| Security bypass | Security Mitigation Bypass | Important | CVE-2018-12825 |
| Out-of-bounds read | Information Disclosure | Important | CVE-2018-12826 |
| Out-of-bounds read | Information Disclosure | Important | CVE-2018-12827 |
| Use of a component with a known vulnerability | Privilege Escalation | Important | CVE-2018-12828 |
All the five security flaws fixed with the August 2018 Patch Tuesday updates have been rated as Important, the most serious one is a privilege escalation issue tracked as CVE-2018-12828 that can lead to arbitrary code execution.
“Adobe has released security updates for Adobe Flash Player for Windows, macOS, Linux and Chrome OS. These updates address important vulnerabilities in Adobe Flash Player 30.0.0.134 and earlier versions. Successful exploitation could lead to arbitrary code execution in the context of the current user.” reads the security advisory published by Adobe.
Adobe fixed two critical arbitrary code execution flaws in Acrobat and Reader (CVE-2018-12808, CVE-2018-12799) for Windows and macOS.
| Vulnerability Category | Vulnerability Impact | Severity | CVE Number |
|---|---|---|---|
| Out-of-bounds write | Arbitrary Code Execution | Critical | CVE-2018-12808 |
| Untrusted pointer dereference | Arbitrary Code Execution | Critical | CVE-2018-12799 |
Adobe also addressed a DLL hijacking vulnerability in the Creative Cloud Desktop Application installer for Windows can lead to privilege escalation.
The last “moderate” issues addressed by Adobe are two cross-site scripting (XSS) flaws that affect the Experience Manager product that can lead to information disclosure and an input validation bypass issue that can be exploited by an attacker to modify information.
Adobe is not aware of attacks in the wild that have exploited the vulnerabilities, and it doesn’t expect to see attacks exploiting them soon.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(Security Affairs – August 2018 Patch Tuesday, Adobe)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/75356/security/august-2018-patch-tuesday.html