Adobe Warns of Multiple Vulnerabilities Across Key Products That Could Allow Arbitrary Code Execution

imagem 27

Security researchers have identified a series of vulnerabilities affecting a range of Adobe products. The most serious of these flaws could potentially allow an attacker to execute arbitrary code on a victim’s system.

  • Adobe Experience Manager (AEM) is an enterprise digital experience platform that merges content management, digital asset management, and digital enrollment into a single cloud-native solution.
  • Adobe ColdFusion is a commercial rapid web application development platform for building, deploying, and scaling dynamic enterprise web and mobile applications.
  • Adobe Photoshop is a professional raster graphics editor for creating, editing, and manipulating digital images.
  • Adobe Illustrator is an industry-standard vector graphics editor and design tool for creating infinitely scalable artwork, logos, icons, typography, and complex illustrations.
  • Adobe Animate is computer animation and multimedia authoring software.
  • Adobe Commerce is a flexible, enterprise-level e-commerce platform built on Magento technology that helps businesses create and manage online stores.
  • Adobe Acrobat Reader is a free application for viewing, printing, signing, sharing, and annotating PDF (Portable Document Format) files.
  • Adobe Campaign Classic is an enterprise marketing automation and cross-channel campaign management platform for designing, executing, and orchestrating customer journeys across online and offline channels.

If the most critical of these vulnerabilities is successfully exploited, an attacker could execute arbitrary code with the same permissions as the logged-in user. Depending on the user’s privilege level, the attacker might be able to install programs, view, modify, or delete data, or create new accounts with full user rights. Users running with limited privileges would likely be less affected than those operating with administrative rights.

Leave a Comment

Your email address will not be published. Required fields are marked *