Threat Advisory

Adobe Addresses Critical Code Execution Flaws in Multiple Products

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Adobe's security updates address multiple critical vulnerabilities across its products, including Acrobat, PDF Reader, Photoshop, and Illustrator. The most severe issues involve memory corruption flaws that could enable arbitrary code execution on both Windows and macOS systems. Specifically, Acrobat and PDF Reader are affected by critical Use After Free and Type Confusion vulnerabilities, while Photoshop contains several critical buffer overflows and out-of-bounds write issues. Illustrator is similarly impacted by critical integer overflow, underflow, and out-of-bounds write vulnerabilities. Adobe also patched vulnerabilities leading to memory leaks and denial-of-service conditions in Photoshop and Illustrator, highlighting the broad range of potential impacts across its product suite. Immediate updates are recommended to mitigate these high-risk threats.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Adobe's security updates address multiple critical vulnerabilities across its products, including Acrobat, PDF Reader, Photoshop, and Illustrator. The most severe issues involve memory corruption flaws that could enable arbitrary code execution on both Windows and macOS systems. Specifically, Acrobat and PDF Reader are affected by critical Use After Free and Type Confusion vulnerabilities, while Photoshop contains several critical buffer overflows and out-of-bounds write issues. Illustrator is similarly impacted by critical integer overflow, underflow, and out-of-bounds write vulnerabilities. Adobe also patched vulnerabilities leading to memory leaks and denial-of-service conditions in Photoshop and Illustrator, highlighting the broad range of potential impacts across its product suite. Immediate updates are recommended to mitigate these high-risk threats.[emaillocker id="1283"]

 

  • CVE-2024-41869: This vulnerability is a Use After Free (UAF) flaw in Adobe Acrobat and PDF Reader. It occurs when memory that has already been freed is accessed, potentially leading to arbitrary code execution. Exploiting this flaw could allow an attacker to gain control over the affected system with elevated privileges.

 

  • CVE-2024-45112: A Type Confusion vulnerability in Adobe Acrobat and PDF Reader, this flaw allows the use of an incorrect data type, leading to arbitrary code execution. By manipulating this flaw, an attacker could execute code remotely and potentially compromise the system.

 

  • CVE-2024-43756: This is a heap-based buffer overflow vulnerability in Adobe Photoshop. It results from improper handling of memory allocation, allowing an attacker to overwrite memory locations and execute arbitrary code, potentially gaining full control over the system.

 

  • CVE-2024-43760: Another critical buffer overflow vulnerability in Adobe Photoshop, this out-of-bounds write occurs when data is written outside the bounds of allocated memory. Exploiting this flaw can result in arbitrary code execution, leading to system compromise.

 

  • CVE-2024-45108: This out-of-bounds write vulnerability in Adobe Photoshop allows data to be written beyond the intended memory space, which could enable an attacker to execute arbitrary code and gain unauthorized access to the system.

 

  • CVE-2024-45109: This vulnerability is also an out-of-bounds write flaw in Adobe Photoshop, leading to arbitrary code execution. Exploiting this issue allows an attacker to alter memory structures and control the affected system.

 

  • CVE-2024-45110: An out-of-bounds read vulnerability in Adobe Photoshop, this flaw could expose sensitive information by allowing access to memory regions beyond their boundaries. Though it only causes a memory leak, it could be exploited to leak critical data.

 

  • CVE-2024-41857: A critical integer underflow vulnerability in Adobe Illustrator, it occurs when a numeric value is reduced beyond its minimum limit, leading to arbitrary code execution. An attacker could exploit this flaw to corrupt memory and take control of the system.

 

  • CVE-2024-34121: This vulnerability in Adobe Illustrator is an integer overflow or wraparound issue. When numbers exceed their maximum value, it results in erroneous memory manipulation, potentially leading to arbitrary code execution.

 

  • CVE-2024-41856: This is an improper input validation vulnerability in Adobe Illustrator. It allows attackers to input unexpected or malicious data, leading to arbitrary code execution. Exploiting this flaw could enable an attacker to compromise the affected system.

 

  • CVE-2024-45114: An out-of-bounds write vulnerability in Adobe Illustrator, this flaw allows attackers to write data outside the buffer’s boundaries, resulting in arbitrary code execution and potential system compromise.

 

  • CVE-2024-43758: A Use After Free vulnerability in Adobe Illustrator, this flaw allows access to previously freed memory, which could lead to arbitrary code execution. An attacker could exploit this issue to gain control of the affected system.

 

  • CVE-2024-45111: This is an out-of-bounds read vulnerability in Adobe Illustrator. It could expose sensitive information from memory, resulting in a memory leak that could potentially be exploited by attackers. Exploitation of this flaw could lead to unauthorized data access, increasing the risk of information leakage.

 

  • CVE-2024-43759: A NULL pointer dereference vulnerability in Adobe Illustrator, this flaw can cause the application to crash or become unavailable, leading to a denial-of-service (DoS) condition. While it doesn’t allow code execution, it could be used to disrupt services.

RECOMMENDATION:

We strongly recommend you update Adobe products as below version:

  • Acrobat DC and Acrobat Reader DC to version 24.003.20112.
  • Adobe Photoshop to version 25.12.
  • Adobe Illustrator to version 28.7.1.

REFERENCES:

The following reports contain further technical details:
https://securityaffairs.com/168313/security/adobe-patch-tuesday-sept-2024.html

[/emaillocker]
crossmenu