CERT-In Advisory
CIAD-2023-0042
Multiple Vulnerabilities in Adobe Products
Original Issue Date: November 23, 2023
Severity Rating: Medium
Software Affected
- ColdFusion 2023 Update 5 and earlier versions
- ColdFusion 2021 Update 11 and earlier versions
- RoboHelp Server RHS 11.4 and earlier versions
- Acrobat DC 23.006.20360 and earlier versions
- Acrobat Reader DC 23.006.20360 and earlier versions
- Acrobat 2020 20.005.30524 and earlier versions
- Acrobat Reader 2020 20.005.30524 and earlier versions
- Adobe InDesign ID18.5 and earlier versions
- Adobe InDesign ID17.4.2 and earlier versions
- Photoshop 2023 24.7.1 and earlier versions
- Photoshop 2024 25.0 and earlier versions
- Adobe Bridge¿ 13.0.4 and earlier versions
- Adobe Bridge¿ 14.0.0 and earlier versions
- Adobe FrameMaker Publishing Server Version - 2022 and earlier versions
- Adobe InCopy¿ 18.5 and earlier versions
- Adobe InCopy¿ 17.4.2 and earlier versions
- Adobe Animate 2023 23.0.2 and earlier versions
- Adobe Dimension 3.4.9 and earlier versions
- Adobe Media Encoder 24.0.2 and earlier versions
- Adobe Media Encoder 23.6 and earlier versions
- Adobe Audition 24.0 and earlier versions
- Adobe Audition 23.6.1 and earlier versions
- Adobe Premiere Pro 24.0 and earlier versions
- Adobe Premiere Pro 23.6 and earlier versions
- Adobe After Effects 24.0.2 and earlier versions
- Adobe After Effects 23.6 and earlier versions
Overview
Multiple vulnerabilities have been reported in Adobe Products, which could allow an attacker to bypass security restrictions, execute arbitrary code remotely, disclose sensitive information and perform denial of service (DoS) conditions on the targeted system.
Description
Multiple vulnerabilities have been reported in Adobe products, details of which are provided below:

Solution
Apply appropriate fixes as mentioned in Adobe Security Bulletin:
https://helpx.adobe.com/security/security-bulletin.html
Vendor Information
Adobe
https://helpx.adobe.com/security/security-bulletin.html
References
Adobe
https://helpx.adobe.com/security/security-bulletin.html
CVE Name
CVE-2023-44350
CVE-2023-26347
CVE-2023-44351
CVE-2023-44352
CVE-2023-44353
CVE-2023-44355
CVE-2023-22272
CVE-2023-22273
CVE-2023-22274
CVE-2023-22275
CVE-2023-22268
CVE-2023-44336
CVE-2023-44337
CVE-2023-44338
CVE-2023-44359
CVE-2023-44365
CVE-2023-44366
CVE-2023-44367
CVE-2023-44371
CVE-2023-44372
CVE-2023-44339
CVE-2023-44340
CVE-2023-44348
CVE-2023-44356
CVE-2023-44357
CVE-2023-44358
CVE-2023-44360
CVE-2023-44361
CVE-2023-44341
CVE-2023-44342
CVE-2023-44343
CVE-2023-44344
CVE-2023-44345
CVE-2023-44346
CVE-2023-44347
CVE-2023-44330
CVE-2023-44331
CVE-2023-44332
CVE-2023-44333
CVE-2023-44334
CVE-2023-44335
CVE-2023-44327
CVE-2023-44328
CVE-2023-44329
CVE-2023-44324
CVE-2023-26368
CVE-2023-44325
CVE-2023-44326
CVE-2023-47040
CVE-2023-47041
CVE-2023-47042
CVE-2023-47043
CVE-2023-47044
CVE-2023-47046
CVE-2023-47047
CVE-2023-47048
CVE-2023-47049
CVE-2023-47050
CVE-2023-47051
CVE-2023-47052
CVE-2023-47053
CVE-2023-47054
CVE-2023-47055
CVE-2023-47056
CVE-2023-47057
CVE-2023-47058
CVE-2023-47059
CVE-2023-47060
CVE-2023-47067
CVE-2023-47068
CVE-2023-47069
CVE-2023-47070
CVE-2023-47071
CVE-2023-47072
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|