ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Adobe Releases Critical Patches for Flash, Acrobat Reader, and Media Encoder

criticalVulnerability exploited in the wildimportance 60CVE-2019-7837CVE-2019-7842

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-7837
Adobe Flash Player versions 32.0.0.171 and earlier, 32.0.0.171 and earlier, and 32.0.0.171 and earlier have a use after free vulnerability.

Adobe Flash Player versions 32.0.0.171 and earlier, 32.0.0.171 and earlier, and 32.0.0.171 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

NVD description · AI analysis pending
8.810%
  • adobe flash player desktop runtime
  • adobe flash player
  • adobe enterprise linux desktop
  • +1 more
CVE-2019-7842
Adobe Media Encoder version 13.0.2 has a use-after-free vulnerability.

Adobe Media Encoder version 13.0.2 has a use-after-free vulnerability. Successful exploitation could lead to remote code execution.

NVD description · AI analysis pending
8.89%
  • adobe media encoder
Full article334 words · extracted from thehackernews.com · click to collapse

Swati KhandelwalMay 14, 2019

Adobe today released its monthly software updates to patch a total of 87 security vulnerabilities in its Adobe Acrobat and Reader, Flash Player and Media Encoder, most of which could lead to arbitrary code execution attacks or worse.

None of the flaws patched this month in Adobe products has been found exploited in the wild.

Out of 87 total flaws, a whopping number of vulnerabilities (i.e., 84 in total) affect Adobe Acrobat and Reader applications alone, where 42 of them are critical and rest 42 are important in severity.

Upon successful exploitation, all critical vulnerabilities in Adobe Acrobat and Reader software lead to arbitrary code execution, allowing attackers to take complete control over targeted systems.

Adobe has released updated versions of Acrobat and Reader software for Windows and macOS operating systems to address these security vulnerabilities.

The update for Adobe Flash Player, which will receive security patch updates until the end of 2020, comes this month with a patch for just one security vulnerability( CVE-2019-7837), which is critical in severity and affects Windows, macOS, Linux, and Chrome OS versions of the software.

The third Adobe product that received patches this month is Media Encoder, a powerful tool that allows users to compress audio and/or video files to be played back across browsers and devices.

Adobe has released Media Encoder version 13.1 that addresses two security vulnerabilities, one of which is critical (CVE-2019-7842) and leads to remote code execution while the second is an information disclosure flaw.

Users of affected Adobe software for Windows, macOS, Linux, and Chrome OS are urged to update their software packages to the latest versions as soon as possible.

If your system hasn't yet detected the availability of the new update automatically, you should manually install the update by choosing "Help → Check for Updates" in your Adobe Acrobat and Reader software.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2019/05/adobe-software-updates.html