CERT-In Vulnerability Note
CIVN-2022-0270
Multiple vulnerabilities in Adobe products
Original Issue Date:June 16, 2022
Severity Rating: HIGH
Software Affected
- Adobe InDesign 17.2.1 and earlier versions for Windows and macOS
- Adobe InDesign 16.4.1 and earlier versions for Windows and macOS
- Adobe InCopy 17.2 and earlier version for Windows and macOS
- Adobe InCopy 16.4.1 and earlier version for Windows and macOS
- Illustrator 2022 26.0.2 and earlier versions for Windows and macOS
- Illustrator 2021 25.4.5 and earlier versions for Windows and macOS
- Adobe Bridge 12.0.1 and earlier versions for Windows and macOS
- Adobe Animate 22.0.5 and earlier versions for Windows and macOS
- RoboHelp Server RHS 11 (Update 3) and earlier versions for Windows
Overview
Multiple vulnerabilities have been reported in Adobe products which could allow an attacker to gain elevated privileges, execute arbitrary code, write arbitrary files on the file system and cause memory leak on the targeted system.
Description
These vulnerabilities exist in Adobe products due to improper Input Validation, improper authorization, heap-based buffer overflow, out-of-bounds Write, out-of-bounds read and use after free flaws. An attacker could exploit these vulnerabilities by persuading the victim to open a specially crafted file or application.
Successful exploitation of these vulnerabilities could allow an attacker to gain elevated privileges, execute arbitrary code, write arbitrary files on the file system and cause memory leak on the targeted system.
Solution
Apply appropriate software updates as mentioned in the Adobe Security updates
https://helpx.adobe.com/security/security-bulletin.html
Vendor Information
Adobe
https://helpx.adobe.com/security/security-bulletin.html
References
Adobe
https://helpx.adobe.com/security/products/animate/apsb22-24.html
https://helpx.adobe.com/security/products/bridge/apsb22-25.html
https://helpx.adobe.com/security/products/illustrator/apsb22-26.html
https://helpx.adobe.com/security/products/incopy/apsb22-29.html
https://helpx.adobe.com/security/products/indesign/apsb22-30.html
https://helpx.adobe.com/security/products/robohelp-server/apsb22-31.html
CVE Name
CVE-2022-28839
CVE-2022-28840
CVE-2022-28841
CVE-2022-28842
CVE-2022-28843
CVE-2022-28844
CVE-2022-28845
CVE-2022-28846
CVE-2022-28847
CVE-2022-28848
CVE-2022-28849
CVE-2022-28850
CVE-2022-30637
CVE-2022-30638
CVE-2022-30639
CVE-2022-30640
CVE-2022-30641
CVE-2022-30642
CVE-2022-30643
CVE-2022-30644
CVE-2022-30645
CVE-2022-30646
CVE-2022-30647
CVE-2022-30648
CVE-2022-30649
CVE-2022-30650
CVE-2022-30651
CVE-2022-30652
CVE-2022-30653
CVE-2022-30654
CVE-2022-30655
CVE-2022-30656
CVE-2022-30657
CVE-2022-30658
CVE-2022-30659
CVE-2022-30660
CVE-2022-30661
CVE-2022-30662
CVE-2022-30663
CVE-2022-30664
CVE-2022-30665
CVE-2022-30666
CVE-2022-30667
CVE-2022-30668
CVE-2022-30669
CVE-2022-30670
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|