CERT-In Vulnerability Note
CIVN-2023-0088
Multiple Vulnerabilities in Adobe
Original Issue Date:March 27, 2023
Updated: December 11, 2023
Severity Rating: CRITICAL
Software Affected
- Adobe Illustrator 2023 27.2.0 and earlier versions for Windows and macOS
- Adobe Dimension version 3.4.7 and earlier versions for Windows and macOS
- Adobe Creative Cloud Desktop Application 5.9.1 and earlier version fo Windows
- Adobe Substance 3D Stager 2.0.0 and earlier versions for Windows and macOS
- Adobe Experience Manager (AEM) 6.5.15.0 and earlier versions and AEM Cloud Service (CS)
- Adobe ColdFusion 2018 prior to Update 16
- Adobe ColdFusion 2021 prior to Update 6
Overview
Multiple vulnerabilities have been reported in Adobe products which could allow an attacker to bypass security restrictions, execute arbitrary code, cause memory leaks and cause denial of service condition on the target system.
Description
These vulnerabilities exist in Adobe Products due to out-of-bounds write / read error, Input validation error, Use-after-free error, Heap-based Buffer Overflow, Integer Overflow or Wraparound, Access of Uninitialized Pointer, Stack-based Buffer Overflow, untrusted search path, access of Memory Location after end of buffer errors, weak cryptography for passwords, cross-site scripting, deserialization of untrusted data, improper access control and improper limitation of a pathname to a restricted directory.
Successful exploitation of these vulnerabilities could allow the attacker to bypass security restrictions, execute arbitrary code, URL Redirection to untrusted site ("Open Redirect"), cause memory leak or information disclosure and cause denial of service condition on the target system.
Note: This vulnerability (CVE-2023-26360) is being exploited in the wild. Users are advised to apply patches urgently.
Solution
Apply appropriate updates as mentioned in the Adobe Security Bulletin:
https://helpx.adobe.com/security.html
Vendor Information
Adobe
https://helpx.adobe.com/security.html
References
Adobe
https://helpx.adobe.com/security/products/illustrator/apsb23-19.html
https://helpx.adobe.com/security/products/dimension/apsb23-20.html
https://helpx.adobe.com/security/products/creative-cloud/apsb23-21.html
https://helpx.adobe.com/security/products/substance3d_stager/apsb23-22.html
https://helpx.adobe.com/security/products/experience-manager/apsb23-18.html
https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html
CISA
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-339a
CVE Name
CVE-2023-21616
CVE-2023-22252
CVE-2023-22253
CVE-2023-22254
CVE-2023-21615
CVE-2023-22256
CVE-2023-22257
CVE-2023-22258
CVE-2023-22259
CVE-2023-22260
CVE-2023-22261
CVE-2023-22262
CVE-2023-22263
CVE-2023-22264
CVE-2023-22265
CVE-2023-22266
CVE-2023-22269
CVE-2023-22271
CVE-2023-26358
CVE-2023-25863
CVE-2023-25864
CVE-2023-25865
CVE-2023-25866
CVE-2023-25867
CVE-2023-25868
CVE-2023-25869
CVE-2023-25870
CVE-2023-25871
CVE-2023-25872
CVE-2023-25873
CVE-2023-25874
CVE-2023-25875
CVE-2023-25876
CVE-2023-25877
CVE-2023-25878
CVE-2023-25859
CVE-2023-25860
CVE-2023-25861
CVE-2023-25862
CVE-2023-26426
CVE-2023-25879
CVE-2023-25880
CVE-2023-25881
CVE-2023-25882
CVE-2023-25883
CVE-2023-25884
CVE-2023-25885
CVE-2023-25886
CVE-2023-25887
CVE-2023-25888
CVE-2023-25889
CVE-2023-25890
CVE-2023-25891
CVE-2023-25892
CVE-2023-25893
CVE-2023-25894
CVE-2023-25895
CVE-2023-25896
CVE-2023-25897
CVE-2023-25898
CVE-2023-25899
CVE-2023-25900
CVE-2023-25901
CVE-2023-25902
CVE-2023-25903
CVE-2023-26359
CVE-2023-26360
CVE-2023-26361
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|